Code:
Alles auswählen Aufklappen ATTFilter
# AdwCleaner v3.205 - Bericht erstellt am 28/04/2014 um 20:47:17
# Aktualisiert 28/04/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzername : hristos - HRISTOS-PC
# Gestartet von : C:\Users\hristos\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : StumbleUponUpdater
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\Perion
Ordner Gelöscht : C:\Program Files\software4u
Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\AskToolbar
Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\SweetIM
Datei Gelöscht : C:\Program Files\Mozilla Firefox\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jifflliplgeajjdhmkcfnngfpgbjonjg
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niogeckbkdcabhnapjbkeiklablhjoca
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pgifblbjgdjhcelbanblbhkhmbnnmhfg
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\StumbleUpon.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Babylon.dskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylnApp.appCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escrtBtn.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\StumbleUpon.QTimeCpio
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\StumbleUpon.QTimeCpio.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\incredibar_installer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_camstudio_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_camstudio_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_portabletor_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_portabletor_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB616CFF-D989-48A8-9C85-E2A8D56AB2CA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}]
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\ImInstaller
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\StumbleUpon
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\lyricsplus
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\StumbleUpon
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\IB Updater
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17041
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v28.0 (de)
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [5825 octets] - [28/04/2014 20:44:33]
AdwCleaner[S0].txt - [5699 octets] - [28/04/2014 20:47:17]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5759 octets] ##########
Code:
Alles auswählen Aufklappen ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by hristos on 28.04.2014 at 20:54:45,42
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-109183035-3835306969-3137161351-1000\Software\ib updater
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\dmwu_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsPls_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsPls_RASMANCS
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\Users\hristos\AppData\Roaming\babylon"
Successfully deleted: [Folder] "C:\Users\hristos\AppData\Roaming\software4u"
Successfully deleted: [Folder] "C:\Users\hristos\appdata\locallow\boost_interprocess"
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{0E666F1C-E472-4EA0-AD05-1B35E09D7EBF}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{0E9BAF09-AE8E-4FBD-8FD8-FE16D769E2E9}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{11AF38A4-D8A0-4C99-AD55-DDA58BFEAB05}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{1351D0C8-7776-41F8-8128-842B78091CBA}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{1BC0BDC5-DF37-4AE0-9372-F6676130023E}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{1F84BE2B-C6C9-4EF6-9516-B736EE313437}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{28EC923A-D06F-4E1A-8EA5-2CBF9FB23FA1}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{2A737C90-ECF6-4211-8108-7D885D4EDD51}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{2A772437-0137-4B94-9C2D-FF67EB22B262}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{2B19B407-B4BC-4516-89F0-03AC57EB9DAD}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{2FD17106-60F2-4F17-B699-F4F10ABDF3E3}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{30C11501-20A1-4B02-84A0-65D22E831E5B}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{31D6D3FB-2489-4528-9253-B0B2F9D9D355}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{324E0231-CC72-4F6D-86AF-82DBE7285DB3}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{3A849A40-AFE4-4B3E-B4AB-74E5E1747A7B}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{4D0B0CAC-14AD-4F4F-B128-EFAF67C25229}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{4EAD9365-8778-4C07-988A-00B1B3ED387B}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{58F66564-448D-4503-8FA6-ED787B38AC83}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{5E0137CB-2BDA-4840-8473-C4D48B1624D0}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{6395C1FA-6BE6-42B5-8FE1-F5B1168D13A3}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{67FB84F9-A5F9-4DE4-9858-03BB4B5DC3B5}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{7408315D-8C28-40EC-B00A-D092774B5190}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{770CD089-7E68-4F48-BF91-D9B9F4E3CE9B}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{8084BD63-11C0-43F2-A76F-35EC0A9F629B}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{83A3AD86-7418-420B-A39E-BBF17ED9521E}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{87CB4A73-F812-462A-84C7-DCCE517256CC}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{8C5C4D59-9BFB-4DFB-A763-D15ABBDFF5E4}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{9082BBAA-2E0A-44BF-9FF9-3FE413BE756B}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{9241B05D-F5B7-4788-884A-E3EDBABDB8E2}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{96469965-7758-4883-8576-5101C01B03A2}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{9C8D1BED-31EA-41AE-92E1-037EF1E1C8AA}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{B671C801-4681-45C2-AD1F-3E90D9710C11}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{BE59669A-DF92-4D04-A3E9-C631FF70FA35}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{BF04C606-A5A9-4020-800C-5B2C29A9CA54}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{C45D9D7A-C17A-4414-B971-F838723329B4}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{C7FC281B-A98D-4ABA-B06D-034C49700DB5}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{CC7885B4-5F1C-408F-893D-0CA93A30247A}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{D1B5CEDC-9E0B-4780-A39E-B93DD0EE0CA6}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{DD8FB64B-4DBB-42DF-A32B-26E02B69EF4A}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{DF1DBF66-F91F-4683-92D4-2515D10D607A}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{E6FA642A-B346-4B16-A507-192BB293A035}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{ED0A60D8-6747-49C4-9CBE-C817ACC10CC5}
Successfully deleted: [Empty Folder] C:\Users\hristos\appdata\local\{F802B32A-C7D9-4809-8381-4392CC234573}
~~~ FireFox
Successfully deleted: [File] C:\user.js
Successfully deleted: [File] C:\Users\hristos\AppData\Roaming\mozilla\firefox\profiles\yufn37b9.default\user.js
Emptied folder: C:\Users\hristos\AppData\Roaming\mozilla\firefox\profiles\yufn37b9.default\minidumps [17 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.04.2014 at 20:57:35,39
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-04-2014
Ran by hristos (administrator) on HRISTOS-PC on 28-04-2014 21:04:23
Running from C:\Users\hristos\Desktop\FRST-OlderVersion
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Windows\system32\PnkBstrA.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Spotify Ltd) C:\Users\hristos\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
() C:\Program Files\Opera\20.0.1387.91\opera_crashreporter.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
(Microsoft Corporation) C:\Windows\system32\wuauclt.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
(Opera Software) C:\Program Files\Opera\20.0.1387.91\opera.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Windows Mobile Device Center] => C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-109183035-3835306969-3137161351-1000\...\Run: [Spotify Web Helper] => C:\Users\hristos\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-12] (Spotify Ltd)
HKU\S-1-5-21-109183035-3835306969-3137161351-1000\...\Run: [iCloudServices] => C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-109183035-3835306969-3137161351-1000\...\Run: [MKLOL] => C:\Program Files\MKJogo\MKLOL\MK.exe [1277128 2014-04-23] (MK)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKLM - DefaultScope value is missing.
BHO: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Plants%20vs.%20Zombies/Images/stg_drm.ocx
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Plants%20vs.%20Zombies/Images/armhelper.ocx
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\hristos\AppData\Roaming\Mozilla\Firefox\Profiles\yufn37b9.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @gamersfirst.com/LiveLauncher - C:\Program Files\GamersFirst\LIVE!\nplivelauncher.dll No File
FF Plugin: @java.com/DTPlugin,version=10.5.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\hristos\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\hristos\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\hristos\AppData\Local\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-01-12]
Chrome:
=======
CHR HomePage:
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\hristos\AppData\Local\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\hristos\AppData\Local\Google\Chrome\Application\34.0.1847.116\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Users\hristos\AppData\Local\Google\Chrome\Application\34.0.1847.116\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.0.147) - C:\Program Files\Java\jre7\bin\new_plugin\npdeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 7) - C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll No File
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Earth Plugin) - C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Windows Live™ Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Facebook Video Calling Plugin) - C:\Users\hristos\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
CHR Extension: (Stylish) - C:\Users\hristos\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe [2013-06-10]
CHR Extension: (Google Wallet) - C:\Users\hristos\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (iOS, iPad, iPhone & iPod Grey Texture) - C:\Users\hristos\AppData\Local\Google\Chrome\User Data\Default\Extensions\odgbpcbfijafedicgoagncajafompaok [2013-09-26]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2011-12-12]
CHR StartMenuInternet: Google Chrome - C:\Users\hristos\AppData\Local\Google\Chrome\Application\chrome.exe
========================== Services (Whitelisted) =================
R2 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [185712 2010-01-28] (TOSHIBA CORPORATION)
R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [75136 2012-11-10] ()
S3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2010-02-05] (TOSHIBA Corporation)
==================== Drivers (Whitelisted) ====================
R3 amdkmdag; C:\Windows\System32\DRIVERS\atipmdag.sys [5340160 2010-03-15] (ATI Technologies Inc.)
S3 EuMusDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\vrtaucbl.sys [50728 2012-09-14] (Eugene V. Muzychenko)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [19720 2009-11-24] (Logitech Inc.)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [39960 2013-05-30] (Logitech Inc.)
S3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [14856 2009-11-24] (Logitech Inc.)
S3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28560 2009-06-17] (Logitech, Inc.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-04-28] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-19] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-19] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-19] (LG Electronics Inc.)
S3 WinRing0_1_2_0; C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [14416 2010-11-01] (OpenLibSys.org)
S3 catchme; \??\C:\Users\hristos\AppData\Local\Temp\catchme.sys [X]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 ew_hwusbdev; system32\DRIVERS\ew_hwusbdev.sys [X]
S3 huawei_enumerator; system32\DRIVERS\ew_jubusenum.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 XDva386; \??\C:\Windows\system32\XDva386.sys [X]
S3 XDva389; \??\C:\Windows\system32\XDva389.sys [X]
S3 XDva390; \??\C:\Windows\system32\XDva390.sys [X]
S3 XDva391; \??\C:\Windows\system32\XDva391.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-28 20:57 - 2014-04-28 20:57 - 00006448 _____ () C:\Users\hristos\Desktop\JRT.txt
2014-04-28 20:54 - 2014-04-28 20:55 - 00000000 ____D () C:\Users\hristos\Desktop\rescue software
2014-04-28 20:54 - 2014-04-28 20:54 - 01016261 _____ (Thisisu) C:\Users\hristos\Desktop\JRT.exe
2014-04-28 20:54 - 2014-04-28 20:54 - 00000000 ____D () C:\Windows\ERUNT
2014-04-28 20:53 - 2014-04-28 20:54 - 01016261 _____ (Thisisu) C:\Users\hristos\Downloads\JRT.exe
2014-04-28 20:45 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-04-28 20:44 - 2014-04-28 20:47 - 00000000 ____D () C:\AdwCleaner
2014-04-28 20:43 - 2014-04-28 20:43 - 01310283 _____ () C:\Users\hristos\Downloads\adwcleaner.exe
2014-04-25 01:46 - 2014-04-25 01:46 - 00000000 ____D () C:\Users\hristos\Desktop\Tor Browser
2014-04-25 01:44 - 2014-04-25 01:44 - 22913908 _____ () C:\Users\hristos\Desktop\torbrowser-install-3.5.4_en-US.exe
2014-04-23 18:16 - 2014-04-23 18:16 - 00000048 _____ () C:\Windows\JQHApp.dat
2014-04-23 18:16 - 2014-04-23 18:16 - 00000000 ____D () C:\Users\hristos\Documents\MK-LOL
2014-04-23 18:09 - 2014-04-23 18:09 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MKJogo
2014-04-23 18:08 - 2014-04-23 18:08 - 00000000 ____D () C:\Program Files\MKJogo
2014-04-23 17:59 - 2014-04-23 18:00 - 07789256 _____ () C:\Users\hristos\Downloads\MK_LOL_1.0.0.39 (1).exe
2014-04-23 17:58 - 2014-04-23 17:59 - 07789256 _____ () C:\Users\hristos\Downloads\MK_LOL_1.0.0.39.exe
2014-04-22 21:18 - 2014-04-22 21:18 - 00706959 _____ () C:\Users\hristos\Downloads\4443.zip
2014-04-22 06:51 - 2014-02-03 23:01 - 00000000 ____D () C:\Users\hristos\Desktop\rads
2014-04-22 06:48 - 2014-04-22 06:48 - 01525501 _____ () C:\Users\hristos\Downloads\2823.zip
2014-04-21 22:13 - 2014-04-21 22:13 - 00017596 _____ () C:\ComboFix.txt
2014-04-21 21:48 - 2014-04-21 22:13 - 00000000 ____D () C:\Qoobox
2014-04-21 21:48 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-21 21:48 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-21 21:48 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-21 21:48 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-21 21:48 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-21 21:48 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-21 21:48 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-21 21:48 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-21 21:47 - 2014-04-21 22:12 - 00000000 ____D () C:\Windows\erdnt
2014-04-21 15:25 - 2014-04-21 15:25 - 00215775 _____ () C:\Users\hristos\Downloads\32923.zip
2014-04-21 15:25 - 2014-04-21 15:25 - 00215775 _____ () C:\Users\hristos\Downloads\32923 (1).zip
2014-04-21 15:23 - 2014-04-21 15:23 - 00032258 _____ () C:\Users\hristos\Downloads\21043 (1).zip
2014-04-21 15:22 - 2014-04-21 15:22 - 00032258 _____ () C:\Users\hristos\Downloads\21043.zip
2014-04-21 15:21 - 2014-04-21 15:21 - 00094864 _____ () C:\Users\hristos\Downloads\3364.zip
2014-04-21 15:13 - 2014-04-21 15:14 - 07916654 _____ () C:\Users\hristos\Downloads\SIU 4.34-Lite.zip
2014-04-20 20:41 - 2014-04-20 20:41 - 11944901 _____ () C:\Users\hristos\Downloads\setup.exe
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\friendbomber.me
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Friend Bomber
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\ProgramData\friendbomber.me
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\Program Files\Friend Bomber
2014-04-20 20:28 - 2014-04-28 21:04 - 00000000 ____D () C:\Users\hristos\Desktop\FRST-OlderVersion
2014-04-20 18:15 - 2014-04-20 18:15 - 00000000 ____D () C:\Users\hristos\AppData\Local\BoLUpdater
2014-04-17 15:14 - 2014-04-17 15:14 - 00035700 _____ () C:\Users\hristos\Downloads\Addition.txt
2014-04-17 15:13 - 2014-04-28 21:04 - 00000000 ____D () C:\FRST
2014-04-17 15:13 - 2014-04-17 15:14 - 00035488 _____ () C:\Users\hristos\Downloads\FRST.txt
2014-04-17 03:16 - 2014-04-17 03:16 - 00000000 _____ () C:\Windows\NDSTray.INI
2014-04-17 03:00 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-17 03:00 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-17 03:00 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-17 03:00 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-17 03:00 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-17 03:00 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-17 03:00 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-17 03:00 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-17 03:00 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-17 03:00 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-17 03:00 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-17 03:00 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-17 03:00 - 2014-03-06 09:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-17 03:00 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-17 03:00 - 2014-03-06 09:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-17 03:00 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-17 03:00 - 2014-03-06 09:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-17 03:00 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-17 03:00 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-17 03:00 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-17 03:00 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-17 03:00 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-17 03:00 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-17 03:00 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-17 03:00 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-17 03:00 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-14 18:27 - 2014-04-28 20:49 - 00002567 _____ () C:\Windows\setupact.log
2014-04-14 18:27 - 2014-04-28 20:48 - 00003338 _____ () C:\Windows\PFRO.log
2014-04-14 18:27 - 2014-04-14 18:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-14 00:06 - 2014-04-14 00:15 - 00000000 ____D () C:\Users\hristos\Desktop\naked
2014-04-12 10:12 - 2014-04-28 20:47 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-11 09:11 - 2014-03-31 22:22 - 00000000 ____D () C:\Users\hristos\Desktop\Skrillex - Recess (2014)
2014-04-09 23:08 - 2014-04-09 23:08 - 00231952 _____ () C:\Users\hristos\Downloads\DriverTurboSetup.exe
2014-04-09 22:48 - 2014-04-17 20:31 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\DriverTurbo
2014-04-09 21:34 - 2014-04-09 21:43 - 38692329 _____ () C:\Users\hristos\Downloads\sound-20100517115314.zip
2014-04-09 21:11 - 2014-04-09 21:25 - 00173651 _____ () C:\Users\hristos\Downloads\sound-20100517111051 (1).zip.opdownload
2014-04-09 20:48 - 2014-04-28 19:47 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-09 20:48 - 2014-04-09 20:48 - 00001020 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-09 20:48 - 2014-04-09 20:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-04-09 20:47 - 2014-04-09 20:47 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware
2014-04-09 20:47 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-09 20:47 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-09 20:47 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-09 20:45 - 2014-04-20 20:05 - 00000000 ____D () C:\Program Files\CONEXANT
2014-04-09 20:44 - 2014-04-09 20:46 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\hristos\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-09 20:31 - 2014-04-09 20:43 - 38692329 _____ () C:\Users\hristos\Downloads\sound-20100517111051.zip
2014-04-09 00:11 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 00:11 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 00:11 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 00:11 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 00:11 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 00:11 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-07 20:12 - 2014-04-07 20:12 - 00000000 ____D () C:\Users\hristos\Desktop\BoL Studio(Full Deal)
2014-04-07 20:12 - 2014-04-07 19:28 - 27055956 _____ () C:\Users\hristos\Desktop\BoL Studio(Full Deal).rar
2014-04-07 20:10 - 2014-04-27 00:59 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\BoL
2014-04-07 20:08 - 2014-04-07 20:09 - 06528512 _____ () C:\Users\hristos\Downloads\BoL.dll
2014-04-07 20:07 - 2014-04-07 20:08 - 01888256 _____ () C:\Users\hristos\Downloads\BoL Studio.exe
2014-04-07 19:26 - 2014-04-07 19:28 - 27055956 _____ () C:\Users\hristos\Downloads\BoL Studio(Full Deal).rar
2014-04-07 19:24 - 2014-04-07 19:24 - 06120184 _____ (TeamViewer GmbH) C:\Users\hristos\Downloads\TeamViewer_Setup_de.exe
2014-04-07 19:01 - 2014-04-07 20:09 - 00000000 ____D () C:\Users\hristos\Desktop\bol
2014-04-07 19:00 - 2014-04-07 19:01 - 10339653 _____ () C:\Users\hristos\Downloads\BoL Studio.rar
==================== One Month Modified Files and Folders =======
2014-04-28 21:04 - 2014-04-20 20:28 - 00000000 ____D () C:\Users\hristos\Desktop\FRST-OlderVersion
2014-04-28 21:04 - 2014-04-17 15:13 - 00000000 ____D () C:\FRST
2014-04-28 21:03 - 2011-10-15 22:26 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-28 20:57 - 2014-04-28 20:57 - 00006448 _____ () C:\Users\hristos\Desktop\JRT.txt
2014-04-28 20:56 - 2009-07-14 06:34 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-28 20:56 - 2009-07-14 06:34 - 00017136 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-28 20:55 - 2014-04-28 20:54 - 00000000 ____D () C:\Users\hristos\Desktop\rescue software
2014-04-28 20:54 - 2014-04-28 20:54 - 01016261 _____ (Thisisu) C:\Users\hristos\Desktop\JRT.exe
2014-04-28 20:54 - 2014-04-28 20:54 - 00000000 ____D () C:\Windows\ERUNT
2014-04-28 20:54 - 2014-04-28 20:53 - 01016261 _____ (Thisisu) C:\Users\hristos\Downloads\JRT.exe
2014-04-28 20:53 - 2011-08-13 02:29 - 01114457 _____ () C:\Windows\WindowsUpdate.log
2014-04-28 20:51 - 2011-10-15 22:26 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-28 20:49 - 2014-04-14 18:27 - 00002567 _____ () C:\Windows\setupact.log
2014-04-28 20:49 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-28 20:48 - 2014-04-14 18:27 - 00003338 _____ () C:\Windows\PFRO.log
2014-04-28 20:47 - 2014-04-28 20:44 - 00000000 ____D () C:\AdwCleaner
2014-04-28 20:47 - 2014-04-12 10:12 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-28 20:43 - 2014-04-28 20:43 - 01310283 _____ () C:\Users\hristos\Downloads\adwcleaner.exe
2014-04-28 20:43 - 2011-09-30 20:37 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\TS3Client
2014-04-28 20:22 - 2011-08-13 12:04 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-109183035-3835306969-3137161351-1000UA.job
2014-04-28 19:47 - 2014-04-09 20:48 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-28 18:40 - 2012-05-08 18:07 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\Spotify
2014-04-28 18:11 - 2011-10-19 21:01 - 00001146 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-109183035-3835306969-3137161351-1000UA.job
2014-04-28 16:22 - 2011-08-13 12:04 - 00001076 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-109183035-3835306969-3137161351-1000Core.job
2014-04-28 00:11 - 2011-10-19 21:01 - 00001124 _____ () C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-109183035-3835306969-3137161351-1000Core.job
2014-04-27 13:30 - 2012-12-13 22:13 - 00116480 _____ () C:\Windows\system32\GDIPFONTCACHEV1.DAT
2014-04-27 03:11 - 2011-08-13 02:37 - 00006252 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-27 00:59 - 2014-04-07 20:10 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\BoL
2014-04-26 17:24 - 2014-03-09 16:11 - 00000000 ____D () C:\Program Files\Steam
2014-04-26 16:44 - 2011-11-12 21:06 - 00000000 ____D () C:\Program Files\Common Files\Steam
2014-04-25 01:46 - 2014-04-25 01:46 - 00000000 ____D () C:\Users\hristos\Desktop\Tor Browser
2014-04-25 01:44 - 2014-04-25 01:44 - 22913908 _____ () C:\Users\hristos\Desktop\torbrowser-install-3.5.4_en-US.exe
2014-04-23 18:16 - 2014-04-23 18:16 - 00000048 _____ () C:\Windows\JQHApp.dat
2014-04-23 18:16 - 2014-04-23 18:16 - 00000000 ____D () C:\Users\hristos\Documents\MK-LOL
2014-04-23 18:09 - 2014-04-23 18:09 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MKJogo
2014-04-23 18:08 - 2014-04-23 18:08 - 00000000 ____D () C:\Program Files\MKJogo
2014-04-23 18:00 - 2014-04-23 17:59 - 07789256 _____ () C:\Users\hristos\Downloads\MK_LOL_1.0.0.39 (1).exe
2014-04-23 17:59 - 2014-04-23 17:58 - 07789256 _____ () C:\Users\hristos\Downloads\MK_LOL_1.0.0.39.exe
2014-04-23 01:52 - 2012-05-08 18:11 - 00000000 ____D () C:\Users\hristos\AppData\Local\Spotify
2014-04-22 21:19 - 2012-03-31 17:38 - 00000000 ___HD () C:\Users\hristos\AppData\Local\.minecraft
2014-04-22 21:18 - 2014-04-22 21:18 - 00706959 _____ () C:\Users\hristos\Downloads\4443.zip
2014-04-22 21:07 - 2013-10-11 19:26 - 00000000 ____D () C:\Users\hristos\Desktop\SIU
2014-04-22 06:48 - 2014-04-22 06:48 - 01525501 _____ () C:\Users\hristos\Downloads\2823.zip
2014-04-21 22:13 - 2014-04-21 22:13 - 00017596 _____ () C:\ComboFix.txt
2014-04-21 22:13 - 2014-04-21 21:48 - 00000000 ____D () C:\Qoobox
2014-04-21 22:13 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-04-21 22:13 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-04-21 22:12 - 2014-04-21 21:47 - 00000000 ____D () C:\Windows\erdnt
2014-04-21 22:10 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-04-21 15:25 - 2014-04-21 15:25 - 00215775 _____ () C:\Users\hristos\Downloads\32923.zip
2014-04-21 15:25 - 2014-04-21 15:25 - 00215775 _____ () C:\Users\hristos\Downloads\32923 (1).zip
2014-04-21 15:23 - 2014-04-21 15:23 - 00032258 _____ () C:\Users\hristos\Downloads\21043 (1).zip
2014-04-21 15:22 - 2014-04-21 15:22 - 00032258 _____ () C:\Users\hristos\Downloads\21043.zip
2014-04-21 15:21 - 2014-04-21 15:21 - 00094864 _____ () C:\Users\hristos\Downloads\3364.zip
2014-04-21 15:14 - 2014-04-21 15:13 - 07916654 _____ () C:\Users\hristos\Downloads\SIU 4.34-Lite.zip
2014-04-20 21:24 - 2012-01-06 02:45 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\Skype
2014-04-20 20:43 - 2012-02-17 00:31 - 00000000 ____D () C:\ProgramData\firebird
2014-04-20 20:41 - 2014-04-20 20:41 - 11944901 _____ () C:\Users\hristos\Downloads\setup.exe
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\friendbomber.me
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Friend Bomber
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\ProgramData\friendbomber.me
2014-04-20 20:41 - 2014-04-20 20:41 - 00000000 ____D () C:\Program Files\Friend Bomber
2014-04-20 20:10 - 2011-10-21 20:45 - 00000000 ____D () C:\Program Files\adf-soft´s Screenshot
2014-04-20 20:09 - 2011-10-15 22:26 - 00000000 ____D () C:\Program Files\Google
2014-04-20 20:06 - 2011-09-04 10:25 - 00000000 ____D () C:\Program Files\MAXON
2014-04-20 20:05 - 2014-04-09 20:45 - 00000000 ____D () C:\Program Files\CONEXANT
2014-04-20 20:05 - 2011-09-04 10:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON
2014-04-20 20:05 - 2011-09-04 10:23 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\MAXON
2014-04-20 20:04 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-04-20 20:02 - 2011-08-13 15:49 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-04-20 20:02 - 2011-08-13 15:48 - 00000000 ____D () C:\ProgramData\Adobe
2014-04-20 20:01 - 2011-08-13 15:49 - 00000000 ____D () C:\Program Files\Adobe
2014-04-20 18:15 - 2014-04-20 18:15 - 00000000 ____D () C:\Users\hristos\AppData\Local\BoLUpdater
2014-04-17 20:31 - 2014-04-09 22:48 - 00000000 ____D () C:\Users\hristos\AppData\Roaming\DriverTurbo
2014-04-17 15:14 - 2014-04-17 15:14 - 00035700 _____ () C:\Users\hristos\Downloads\Addition.txt
2014-04-17 15:14 - 2014-04-17 15:13 - 00035488 _____ () C:\Users\hristos\Downloads\FRST.txt
2014-04-17 03:54 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-04-17 03:16 - 2014-04-17 03:16 - 00000000 _____ () C:\Windows\NDSTray.INI
2014-04-17 03:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-04-16 04:09 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-04-14 18:59 - 2011-12-15 08:25 - 00116480 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-14 18:27 - 2014-04-14 18:27 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-14 00:15 - 2014-04-14 00:06 - 00000000 ____D () C:\Users\hristos\Desktop\naked
2014-04-13 23:57 - 2013-04-26 20:47 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-09 23:08 - 2014-04-09 23:08 - 00231952 _____ () C:\Users\hristos\Downloads\DriverTurboSetup.exe
2014-04-09 21:43 - 2014-04-09 21:34 - 38692329 _____ () C:\Users\hristos\Downloads\sound-20100517115314.zip
2014-04-09 21:26 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\L2Schemas
2014-04-09 21:25 - 2014-04-09 21:11 - 00173651 _____ () C:\Users\hristos\Downloads\sound-20100517111051 (1).zip.opdownload
2014-04-09 20:48 - 2014-04-09 20:48 - 00001020 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-04-09 20:48 - 2014-04-09 20:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-04-09 20:47 - 2014-04-09 20:47 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware
2014-04-09 20:47 - 2012-03-03 11:43 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-09 20:46 - 2014-04-09 20:44 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\hristos\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-09 20:43 - 2014-04-09 20:31 - 38692329 _____ () C:\Users\hristos\Downloads\sound-20100517111051.zip
2014-04-09 14:08 - 2013-07-30 16:39 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 14:05 - 2013-08-15 07:39 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 14:00 - 2012-03-08 18:03 - 88028728 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-07 20:12 - 2014-04-07 20:12 - 00000000 ____D () C:\Users\hristos\Desktop\BoL Studio(Full Deal)
2014-04-07 20:09 - 2014-04-07 20:08 - 06528512 _____ () C:\Users\hristos\Downloads\BoL.dll
2014-04-07 20:09 - 2014-04-07 19:01 - 00000000 ____D () C:\Users\hristos\Desktop\bol
2014-04-07 20:08 - 2014-04-07 20:07 - 01888256 _____ () C:\Users\hristos\Downloads\BoL Studio.exe
2014-04-07 19:28 - 2014-04-07 20:12 - 27055956 _____ () C:\Users\hristos\Desktop\BoL Studio(Full Deal).rar
2014-04-07 19:28 - 2014-04-07 19:26 - 27055956 _____ () C:\Users\hristos\Downloads\BoL Studio(Full Deal).rar
2014-04-07 19:24 - 2014-04-07 19:24 - 06120184 _____ (TeamViewer GmbH) C:\Users\hristos\Downloads\TeamViewer_Setup_de.exe
2014-04-07 19:01 - 2014-04-07 19:00 - 10339653 _____ () C:\Users\hristos\Downloads\BoL Studio.rar
2014-04-05 22:45 - 2014-03-12 15:53 - 00000000 ____D () C:\Program Files\Opera
2014-04-03 09:51 - 2014-04-09 20:47 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-09 20:47 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-09 20:47 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-03 03:01 - 2012-05-02 05:53 - 00002077 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-04-03 03:01 - 2011-08-13 02:44 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-04-03 03:01 - 2011-08-13 02:42 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-04-02 20:18 - 2011-10-20 21:47 - 00000000 ____D () C:\Users\hristos\AppData\Local\Windows Live
2014-04-01 20:07 - 2011-08-13 15:49 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2014-03-31 22:22 - 2014-04-11 09:11 - 00000000 ____D () C:\Users\hristos\Desktop\Skrillex - Recess (2014)
Files to move or delete:
====================
C:\Users\hristos\Setup.bat
Some content of TEMP:
====================
C:\Users\hristos\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-19 00:51
==================== End Of Log ============================
--- --- ---
malwarebyte hat nichts gefunden