|
Plagegeister aller Art und deren Bekämpfung: Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.07.2014, 20:35 | #1 |
| Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw) Hallo. Seit heute habe ich einige Probleme mit meinem PC und habe keine Ahnung mehr was ich noch machen kann. Hab schon im Internet gesucht nach Lösungen aber nichts hat geholfen. Nun bin ich auf das Forum hier gestoßen und hoffe man kann mir helfen. 1. Problem: Es sind überall auf vielen Websites Wörter grün markiert und unterstrichen die mir irgendwelche Downloads oderso andrehen wollen. 2. Problem: Es öffnet sich dauernd ein leeres popup-fenster von "cdn.cloudwm.com" 3. Problem: Extrem viele Websites werden nichtmehr geladen, z.b. facebook, google usw. Zuerst läd es nur und es wird angezeigt dass versucht wird eine "sichere Verbindung" herzustellen, und dann kommt aber ein "SSL Verbindungsfehler". Diese seite hier funktioniert allerdings, und als suchmaschine musste ich dann bing nutzen, das auch funktionierte. Weitere Infos: -Habe Win8.1 -Anti Viren Programm ist "Avast Free Antivirus" -Ich nutze Chrome, aber die Probleme sind auch in IE und Firefox vorhanden. -Hab schon einige "Cleaner" Programme laufen gelassen und es wurde kaum was gefunden. -Wenn ich das "Junkware Removal Tool by Thisisu" laufen lasse, sind all die Probleme weg und es funktioniert wieder alles. Das Tool schließt anscheinend zwecks Überprüfung viele Sachen, u.a. auch mein AVAST. Aber wenn ich den PC dann neustarte sind alle Probleme sofort wieder genauso da. -Vor längerer Zeit hab ich irgendwo ausversehn mal das Programm "HD Streamer" installiert auf meinem pc, aber ich finde da nichts wie ich das deinstallieren könnte, ich finde keinen Ordner in den Programmen, und im CCleaner bei "Programme deinstallieren" wird es auch nicht angezeigt. Und laut google soll das Programm wohl nicht so ganz "sauber" sein. Mehr kann ich dazu glaube ich erstmal nicht sagen. Hoffe ihr könnt mir helfen. Mfg |
14.07.2014, 20:42 | #2 |
/// the machine /// TB-Ausbilder | Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw) hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
14.07.2014, 20:48 | #3 |
| Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw)FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 14-07-2014 01 Ran by manuf_000 (administrator) on MANU-PC on 14-07-2014 21:45:06 Running from C:\Users\manuf_000\Desktop Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Elex do Brasil Participações Ltda) C:\Program Files (x86)\iSafe\iSafeTray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe () C:\Program Files (x86)\Isis\isis.exe () C:\Program Files (x86)\iSafe\ipcdl.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (POTI, Inc.) C:\Program Files (x86)\Songbird\songbird.exe (Microsoft Corporation) C:\Windows\System32\audiodg.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech, Inc.) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation) HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2012-03-07] (Intel Corporation) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-11-28] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-07-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [606024 2013-09-19] (BlueStack Systems, Inc.) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4086432 2014-07-14] (AVAST Software) HKLM-x32\...\Run: [Isis] => C:\Program Files (x86)\Isis\Isis.exe [330544 2014-07-14] () HKU\S-1-5-21-2245968268-1096486666-1822319797-1002\...\Run: [ACEStream] => C:\Users\manuf_000\AppData\Roaming\ACEStream\engine\ace_engine.exe [26744 2014-07-09] () HKU\S-1-5-21-2245968268-1096486666-1822319797-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [2990304 2013-10-30] (Nota Inc.) HKU\S-1-5-21-2245968268-1096486666-1822319797-1002\...\Run: [DAEMON Tools Ultra Agent] => C:\Program Files (x86)\DAEMON Tools Ultra\DTAgent.exe [3125976 2013-09-23] (Disc Soft Ltd) HKU\S-1-5-21-2245968268-1096486666-1822319797-1002\...\Run: [Amazon Cloud Player] => C:\Users\manuf_000\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3140608 2014-01-14] () HKU\S-1-5-21-2245968268-1096486666-1822319797-1002\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [759496 2014-01-17] (Sandboxie Holdings, LLC) HKU\S-1-5-21-2245968268-1096486666-1822319797-1002\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-2245968268-1096486666-1822319797-1002\...\MountPoints2: {96fdfa0e-2af0-11e3-80d5-3085a9b2b367} - "J:\setup.exe" /autorun AppInit_DLLs: C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL => C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL File Not Found Startup: C:\Users\manuf_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe () ShellIconOverlayIdentifiers: AccExtIco1 -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll () ShellIconOverlayIdentifiers: AccExtIco2 -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll () ShellIconOverlayIdentifiers: AccExtIco3 -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll () ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.5 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x60FC8E625C9DCF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank URLSearchHook: HKCU - (No Name) - {c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File SearchScopes: HKLM - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM - {1EAAB117-8F9D-49BF-885B-D172B38CD11E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKLM-x32 - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKLM-x32 - {1EAAB117-8F9D-49BF-885B-D172B38CD11E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS SearchScopes: HKCU - DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKCU - {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms} SearchScopes: HKCU - {1EAAB117-8F9D-49BF-885B-D172B38CD11E} URL = BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO-x32: No Name -> {15fb1f46-b134-44d8-9394-8b3d2ad4c613} -> No File BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: No Name -> {b336fa49-0cd2-4148-931e-ebbac25b5015} -> No File BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKCU - No Name - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\manuf_000\AppData\Roaming\Mozilla\Firefox\Profiles\lwje90ac.default FF Homepage: about:blank FF NewTab: about:blank FF DefaultSearchEngine: Google FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.19 - C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 - C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc) FF Plugin-x32: @videolan.org/vlc,version=2.0.4 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems) FF Plugin HKCU: @acestream.net/acestreamplugin,version=2.0.14 - C:\Users\manuf_000\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\manuf_000\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\manuf_000\AppData\Roaming\Mozilla\Firefox\Profiles\lwje90ac.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-07] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-03-20] FF HKLM-x32\...\Firefox\Extensions: [ext@WebexpEnhancedV1alpha9097.net] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha9097\ff FF HKLM-x32\...\Firefox\Extensions: [ext@MediaWatchV1home659.net] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home659\ff FF HKCU\...\Firefox\Extensions: [magicplayer@torrentstream.org] - C:\Users\manuf_000\AppData\Roaming\ACEStream\extensions\firefox\magicplayer@torrentstream.org Chrome: ======= CHR HomePage: about:blank CHR StartupUrls: "about:blank" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Extension: (Magic Actions for YouTube™) - C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2012-12-07] CHR Extension: (Adblock Plus) - C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-12-07] CHR Extension: (HTTPS Everywhere) - C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcbommkclmclpchllfjekcdonpmejbdp [2014-07-14] CHR Extension: (FoxyProxy Standard) - C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcknhkkoolaabfmlnjonogaaifnjlfnp [2014-07-14] CHR Extension: (FVD Downloader) - C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp [2014-07-14] CHR Extension: (Google Mail-Checker) - C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2012-12-07] CHR Extension: (Google Wallet) - C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-22] CHR HKLM-x32\...\Chrome\Extension: [badedelkhpmnedjebaagihcljoeeanac] - C:\Program Files (x86)\MediaWatchV1\MediaWatchV1home659\ch\MediaWatchV1home659.crx [2013-08-22] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-14] CHR HKLM-x32\...\Chrome\Extension: [pkjhpnaaeepplepkammdfpibjjmogceh] - C:\Program Files (x86)\WebexpEnhancedV1\WebexpEnhancedV1alpha9097\ch\WebexpEnhancedV1alpha9097.crx [2014-07-14] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-14] (AVAST Software) S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-09-19] (BlueStack Systems, Inc.) R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-09-19] (BlueStack Systems, Inc.) S3 Disc Soft Bus Service; C:\Program Files (x86)\DAEMON Tools Ultra\DiscSoftBusService.exe [654552 2013-09-23] (Disc Soft Ltd) R2 iSafeService; C:\Program Files (x86)\iSafe\iSafeSvc.exe [118048 2014-07-11] (Elex do Brasil Participações Ltda) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [163608 2012-03-07] (Intel Corporation) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [187592 2014-01-17] (Sandboxie Holdings, LLC) R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2012-05-04] (VIA Technologies, Inc.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-14] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-14] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-14] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-14] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-14] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-14] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-14] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-14] () R3 AU8168; C:\Windows\system32\DRIVERS\au630x64.sys [792648 2013-09-23] (Realtek ) R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-09-19] (BlueStack Systems) R3 dtscsibus; C:\Windows\system32\DRIVERS\dtscsibus.sys [29696 2013-12-10] (Disc Soft Ltd) S1 HssDRV6; C:\Windows\system32\DRIVERS\hssdrv6.sys [46280 2013-02-22] (AnchorFree Inc.) U1 iSafeKrnl; C:\Program Files (x86)\iSafe\iSafeKrnl.sys [247488 2014-07-11] (Elex do Brasil Participações Ltda) S3 iSafeKrnlBoot; C:\Windows\System32\DRIVERS\iSafeKrnlBoot.sys [45248 2014-07-11] (Elex do Brasil Participações Ltda) R1 iSafeKrnlKit; C:\Program Files (x86)\iSafe\iSafeKrnlKit.sys [78016 2014-07-11] (Elex do Brasil Participações Ltda) R1 iSafeKrnlR3; C:\Program Files (x86)\iSafe\iSafeKrnlR3.sys [65216 2014-07-11] (Elex do Brasil Participações Ltda) R1 iSafeNetFilter; C:\Program Files (x86)\iSafe\iSafeNetFilter.sys [48640 2014-07-09] (Elex do Brasil Participações Ltda) R1 isis; C:\Windows\System32\drivers\isis.sys [52016 2014-07-14] (Windows (R) Win 7 DDK provider) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [202600 2014-01-17] (Sandboxie Holdings, LLC) S3 taphss6; C:\Windows\system32\DRIVERS\taphss6.sys [42184 2013-04-03] (Anchorfree Inc.) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation) S3 WsAudio_Device; C:\Windows\system32\drivers\VirtualAudio.sys [31080 2013-04-01] (Wondershare) R3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-07-14 21:45 - 2014-07-14 21:45 - 00022302 _____ () C:\Users\manuf_000\Desktop\FRST.txt 2014-07-14 21:44 - 2014-07-14 21:45 - 00000000 ____D () C:\FRST 2014-07-14 21:43 - 2014-07-14 21:43 - 02086912 _____ (Farbar) C:\Users\manuf_000\Desktop\FRST64.exe 2014-07-14 20:59 - 2014-07-14 20:59 - 00000905 _____ () C:\Users\manuf_000\Desktop\JRT.txt 2014-07-14 20:59 - 2014-07-14 20:59 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\iSafe 2014-07-14 20:37 - 2014-07-14 20:37 - 00002277 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-14 20:37 - 2014-07-14 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-07-14 20:28 - 2014-07-14 20:52 - 00018724 _____ () C:\WINDOWS\WindowsUpdate.log 2014-07-14 20:21 - 2014-07-14 20:21 - 00000360 _____ () C:\WINDOWS\PFRO.log 2014-07-14 20:18 - 2014-07-14 21:35 - 00000000 ____D () C:\Program Files (x86)\iSafe 2014-07-14 20:18 - 2014-07-14 20:18 - 00806512 _____ (Elex do Brasil Participações Ltda) C:\Users\manuf_000\Desktop\yet_another_cleaner_bbs.exe 2014-07-14 20:18 - 2014-07-14 20:18 - 00001808 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\YAC.lnk 2014-07-14 20:18 - 2014-07-14 20:18 - 00001802 _____ () C:\Users\Public\Desktop\YAC.lnk 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\WINDOWS\system32\log 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\eCyber 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC 2014-07-14 20:18 - 2014-07-11 14:28 - 00045248 _____ (Elex do Brasil Participações Ltda) C:\WINDOWS\system32\Drivers\iSafeKrnlBoot.sys 2014-07-14 19:47 - 2014-07-14 19:47 - 02347384 _____ (ESET) C:\Users\manuf_000\Desktop\esetsmartinstaller_enu.exe 2014-07-14 19:46 - 2014-07-14 19:46 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\manuf_000\Desktop\sc-cleaner.exe 2014-07-14 19:46 - 2014-07-14 19:46 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-14 19:02 - 2014-07-14 19:02 - 01016261 _____ (Thisisu) C:\Users\manuf_000\Desktop\JRT.exe 2014-07-14 19:02 - 2014-07-14 19:02 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-14 18:58 - 2014-07-14 19:00 - 00000000 ____D () C:\AdwCleaner 2014-07-14 18:58 - 2014-07-14 18:58 - 01348263 _____ () C:\Users\manuf_000\Desktop\adwcleaner_3.215.exe 2014-07-14 18:35 - 2014-07-14 18:35 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2014-07-14 18:35 - 2014-07-14 18:35 - 00001988 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-07-14 18:19 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll 2014-07-14 17:53 - 2014-07-14 17:53 - 00000000 ____D () C:\Program Files (x86)\Isis 2014-07-14 16:44 - 2014-07-14 16:54 - 00000000 ____D () C:\Users\manuf_000\Desktop\Neuer Ordner 2014-07-14 16:41 - 2014-07-14 16:41 - 00052016 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\isis.sys 2014-07-10 00:25 - 2014-07-10 00:25 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-09 14:10 - 2014-04-14 05:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll 2014-07-09 01:41 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-07-09 01:41 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-07-09 01:41 - 2014-06-19 01:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-07-09 01:41 - 2014-06-19 00:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-07-09 01:41 - 2014-06-17 00:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-07-09 01:41 - 2014-06-17 00:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-07-09 01:41 - 2014-06-06 16:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys 2014-07-09 01:41 - 2014-05-30 05:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2014-07-09 01:41 - 2014-05-29 14:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2014-07-09 01:41 - 2014-05-29 09:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll 2014-07-09 01:41 - 2014-05-29 08:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll 2014-07-09 01:41 - 2014-05-29 08:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll 2014-07-09 01:41 - 2014-05-29 07:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll 2014-07-09 01:41 - 2014-05-29 07:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll 2014-07-09 01:40 - 2014-07-01 00:45 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2014-07-09 01:40 - 2014-06-28 09:48 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2014-07-09 01:40 - 2014-06-28 09:07 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2014-07-09 01:40 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-07-09 01:40 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-07-09 01:40 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-07-09 01:40 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-07-09 01:40 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-07-09 01:40 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-07-09 01:40 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-07-09 01:40 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-07-09 01:40 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-07-09 01:40 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-07-09 01:40 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-07-09 01:40 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-07-09 01:40 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-07-09 01:40 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-07-09 01:40 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-07-09 01:40 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-07-09 01:40 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-07-09 01:40 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-07-09 01:40 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-07-09 01:40 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-07-09 01:40 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-07-09 01:40 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-07-09 01:40 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-07-09 01:40 - 2014-06-06 15:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll 2014-07-09 01:40 - 2014-06-06 14:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll 2014-07-09 01:40 - 2014-05-31 12:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe 2014-07-09 01:40 - 2014-05-31 12:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2014-07-09 01:40 - 2014-05-31 05:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll 2014-07-09 01:40 - 2014-05-31 05:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll 2014-07-09 01:40 - 2014-05-31 05:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 01:40 - 2014-05-31 05:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll 2014-07-09 01:40 - 2014-05-31 05:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll 2014-07-09 01:40 - 2014-05-31 05:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-07-09 01:40 - 2014-05-31 04:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll 2014-07-09 01:40 - 2014-05-31 04:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll 2014-07-09 01:40 - 2014-05-31 04:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2014-07-09 01:40 - 2014-05-31 04:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll 2014-07-09 01:40 - 2014-05-31 04:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll 2014-07-09 01:40 - 2014-05-31 04:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll 2014-07-09 01:40 - 2014-05-31 04:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll 2014-07-09 01:39 - 2014-07-09 01:39 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe ==================== One Month Modified Files and Folders ======= 2014-07-14 21:45 - 2014-07-14 21:45 - 00022302 _____ () C:\Users\manuf_000\Desktop\FRST.txt 2014-07-14 21:45 - 2014-07-14 21:44 - 00000000 ____D () C:\FRST 2014-07-14 21:43 - 2014-07-14 21:43 - 02086912 _____ (Farbar) C:\Users\manuf_000\Desktop\FRST64.exe 2014-07-14 21:35 - 2014-07-14 20:18 - 00000000 ____D () C:\Program Files (x86)\iSafe 2014-07-14 21:08 - 2012-12-07 22:19 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-14 21:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2014-07-14 21:00 - 2012-12-07 22:24 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2245968268-1096486666-1822319797-1002 2014-07-14 20:59 - 2014-07-14 20:59 - 00000905 _____ () C:\Users\manuf_000\Desktop\JRT.txt 2014-07-14 20:59 - 2014-07-14 20:59 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\iSafe 2014-07-14 20:52 - 2014-07-14 20:28 - 00018724 _____ () C:\WINDOWS\WindowsUpdate.log 2014-07-14 20:50 - 2013-10-30 06:02 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2014-07-14 20:38 - 2013-09-30 06:14 - 01980934 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2014-07-14 20:38 - 2013-09-30 05:56 - 00841326 _____ () C:\WINDOWS\system32\perfh007.dat 2014-07-14 20:38 - 2013-09-30 05:56 - 00191558 _____ () C:\WINDOWS\system32\perfc007.dat 2014-07-14 20:37 - 2014-07-14 20:37 - 00002277 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-07-14 20:37 - 2014-07-14 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-07-14 20:37 - 2012-12-07 22:19 - 00000000 ____D () C:\Program Files (x86)\Google 2014-07-14 20:34 - 2013-12-10 08:33 - 00000000 __RDO () C:\Users\manuf_000\SkyDrive 2014-07-14 20:34 - 2013-12-10 08:25 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-14 20:34 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2014-07-14 20:34 - 2012-12-07 22:19 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-14 20:33 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2014-07-14 20:32 - 2013-07-06 03:04 - 00000000 ____D () C:\Program Files (x86)\FreeTime 2014-07-14 20:21 - 2014-07-14 20:21 - 00000360 _____ () C:\WINDOWS\PFRO.log 2014-07-14 20:19 - 2013-12-10 08:26 - 00000000 ___RD () C:\Users\manuf_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2014-07-14 20:19 - 2013-12-10 08:23 - 00000000 ___DC () C:\WINDOWS\Panther 2014-07-14 20:19 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2014-07-14 20:19 - 2013-08-21 19:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DevPro 2014-07-14 20:19 - 2013-03-01 19:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Xbox 360 Accessories 2014-07-14 20:19 - 2012-12-10 08:39 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-07-14 20:19 - 2012-12-10 08:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2014-07-14 20:18 - 2014-07-14 20:18 - 00806512 _____ (Elex do Brasil Participações Ltda) C:\Users\manuf_000\Desktop\yet_another_cleaner_bbs.exe 2014-07-14 20:18 - 2014-07-14 20:18 - 00001808 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\YAC.lnk 2014-07-14 20:18 - 2014-07-14 20:18 - 00001802 _____ () C:\Users\Public\Desktop\YAC.lnk 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\WINDOWS\system32\log 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\WINDOWS\Minidump 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\eCyber 2014-07-14 20:18 - 2014-07-14 20:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YAC 2014-07-14 19:47 - 2014-07-14 19:47 - 02347384 _____ (ESET) C:\Users\manuf_000\Desktop\esetsmartinstaller_enu.exe 2014-07-14 19:46 - 2014-07-14 19:46 - 00441592 _____ (Bleeping Computer, LLC) C:\Users\manuf_000\Desktop\sc-cleaner.exe 2014-07-14 19:46 - 2014-07-14 19:46 - 00001770 _____ () C:\sc-cleaner.txt 2014-07-14 19:17 - 2012-12-19 10:43 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\Skype 2014-07-14 19:02 - 2014-07-14 19:02 - 01016261 _____ (Thisisu) C:\Users\manuf_000\Desktop\JRT.exe 2014-07-14 19:02 - 2014-07-14 19:02 - 00000000 ____D () C:\WINDOWS\ERUNT 2014-07-14 19:00 - 2014-07-14 18:58 - 00000000 ____D () C:\AdwCleaner 2014-07-14 18:58 - 2014-07-14 18:58 - 01348263 _____ () C:\Users\manuf_000\Desktop\adwcleaner_3.215.exe 2014-07-14 18:41 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF 2014-07-14 18:41 - 2012-12-13 01:43 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\uTorrent 2014-07-14 18:35 - 2014-07-14 18:35 - 00043152 _____ (AVAST Software) C:\WINDOWS\avastSS.scr 2014-07-14 18:35 - 2014-07-14 18:35 - 00001988 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-07-14 18:35 - 2014-05-01 00:39 - 00029208 _____ () C:\WINDOWS\system32\Drivers\aswHwid.sys 2014-07-14 18:35 - 2014-01-02 16:00 - 00092008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswstm.sys 2014-07-14 18:35 - 2013-03-20 10:12 - 01041168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys 2014-07-14 18:35 - 2013-03-20 10:12 - 00427360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsp.sys 2014-07-14 18:35 - 2013-03-20 10:12 - 00224896 _____ () C:\WINDOWS\system32\Drivers\aswVmm.sys 2014-07-14 18:35 - 2013-03-20 10:12 - 00093568 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2014-07-14 18:35 - 2013-03-20 10:12 - 00079184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2014-07-14 18:35 - 2013-03-20 10:12 - 00065776 _____ () C:\WINDOWS\system32\Drivers\aswRvrt.sys 2014-07-14 18:35 - 2013-03-20 10:12 - 00003924 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update 2014-07-14 18:35 - 2012-12-19 10:57 - 00307344 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2014-07-14 18:31 - 2013-12-18 02:12 - 00003942 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{A2793940-86E8-467E-8EA8-A1A936F70078} 2014-07-14 17:53 - 2014-07-14 17:53 - 00000000 ____D () C:\Program Files (x86)\Isis 2014-07-14 17:06 - 2012-12-08 00:32 - 60402688 ___SH () C:\Users\manuf_000\Desktop\Thumbs.db 2014-07-14 16:54 - 2014-07-14 16:44 - 00000000 ____D () C:\Users\manuf_000\Desktop\Neuer Ordner 2014-07-14 16:41 - 2014-07-14 16:41 - 00052016 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\Drivers\isis.sys 2014-07-14 15:26 - 2012-12-07 23:36 - 00000000 ____D () C:\Users\manuf_000\Documents\TrackMania 2014-07-14 03:40 - 2012-12-11 02:00 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\vlc 2014-07-14 02:00 - 2013-03-20 05:13 - 00000000 ____D () C:\Users\manuf_000\AppData\Local\Adobe 2014-07-12 01:13 - 2012-12-09 05:26 - 24668160 ___SH () C:\Users\manuf_000\Downloads\Thumbs.db 2014-07-11 14:28 - 2014-07-14 20:18 - 00045248 _____ (Elex do Brasil Participações Ltda) C:\WINDOWS\system32\Drivers\iSafeKrnlBoot.sys 2014-07-11 03:54 - 2013-12-10 08:26 - 00000000 ____D () C:\Users\manuf_000 2014-07-11 03:52 - 2013-10-09 22:41 - 00000000 ___RD () C:\Users\manuf_000\Documents\x 2014-07-10 18:35 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2014-07-10 01:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache 2014-07-10 00:26 - 2013-08-22 16:44 - 05063808 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2014-07-10 00:25 - 2014-07-10 00:25 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel 2014-07-10 00:25 - 2013-08-26 01:48 - 00000000 ____D () C:\WINDOWS\system32\MRT 2014-07-10 00:25 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData 2014-07-10 00:25 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 00:25 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2014-07-10 00:25 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore 2014-07-10 00:24 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2014-07-10 00:24 - 2012-12-13 20:33 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2014-07-09 14:10 - 2013-09-30 05:59 - 00000000 ____D () C:\Program Files\Windows Journal 2014-07-09 14:10 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2014-07-09 01:39 - 2014-07-09 01:39 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe 2014-07-09 00:46 - 2014-03-19 07:58 - 00001774 _____ () C:\WINDOWS\Sandboxie.ini 2014-07-08 19:50 - 2013-10-30 06:02 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2014-07-04 10:56 - 2013-07-26 11:57 - 00000000 ____D () C:\Users\manuf_000\AppData\Roaming\.ACEStream 2014-07-01 05:12 - 2013-08-10 01:11 - 00000000 ___HD () C:\_acestream_cache_ 2014-07-01 00:45 - 2014-07-09 01:40 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll 2014-06-28 09:48 - 2014-07-09 01:40 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll 2014-06-28 09:07 - 2014-07-09 01:40 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll 2014-06-26 22:55 - 2013-08-22 17:38 - 00703968 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2014-06-26 22:55 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2014-06-22 22:12 - 2013-04-17 08:50 - 00000000 ____D () C:\Fraps 2014-06-20 23:03 - 2012-12-07 22:19 - 00004104 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-20 23:03 - 2012-12-07 22:19 - 00003868 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2014-06-19 03:39 - 2014-07-09 01:41 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2014-06-19 02:48 - 2014-07-09 01:40 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2014-06-19 02:16 - 2014-07-09 01:41 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2014-06-19 02:09 - 2014-07-09 01:40 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll 2014-06-19 01:51 - 2014-07-09 01:40 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2014-06-19 01:50 - 2014-07-09 01:40 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll 2014-06-19 01:48 - 2014-07-09 01:40 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll 2014-06-19 01:46 - 2014-07-09 01:41 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2014-06-19 01:39 - 2014-07-09 01:40 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe 2014-06-19 01:33 - 2014-07-09 01:40 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2014-06-19 01:32 - 2014-07-09 01:40 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2014-06-19 01:27 - 2014-07-09 01:40 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2014-06-19 01:12 - 2014-07-09 01:40 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll 2014-06-19 00:59 - 2014-07-09 01:40 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll 2014-06-19 00:58 - 2014-07-09 01:40 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2014-06-19 00:58 - 2014-07-09 01:40 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll 2014-06-19 00:57 - 2014-07-09 01:41 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2014-06-19 00:52 - 2014-07-09 01:40 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2014-06-19 00:51 - 2014-07-09 01:40 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2014-06-19 00:49 - 2014-07-09 01:40 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2014-06-19 00:45 - 2014-07-09 01:40 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2014-06-19 00:35 - 2014-07-09 01:40 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2014-06-19 00:34 - 2014-07-09 01:40 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2014-06-19 00:15 - 2014-07-09 01:40 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2014-06-19 00:13 - 2014-07-09 01:40 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2014-06-19 00:09 - 2014-07-09 01:40 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2014-06-19 00:07 - 2014-07-09 01:40 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2014-06-18 16:55 - 2014-06-06 21:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-06-17 23:50 - 2013-10-26 21:21 - 00000000 ____D () C:\Users\manuf_000\temp 2014-06-17 23:50 - 2013-10-26 21:19 - 00000902 _____ () C:\Users\manuf_000\AppData\Roaming\__AvidCloudManager.log 2014-06-17 23:48 - 2013-10-26 21:19 - 00006293 _____ () C:\Users\manuf_000\AppData\Roaming\MANU-PC.MTBF.txt 2014-06-17 23:48 - 2013-10-26 21:19 - 00000000 ____D () C:\Users\manuf_000\AppData\Local\Avid 2014-06-17 23:48 - 2013-10-26 21:08 - 00000349 _____ () C:\Users\Public\Documents\PCLECHAL.INI 2014-06-17 00:26 - 2014-07-09 01:41 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe 2014-06-17 00:24 - 2014-07-09 01:41 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe 2014-06-14 23:13 - 2014-05-23 05:05 - 00000000 ____D () C:\Users\manuf_000\Downloads\Portscanner Some content of TEMP: ==================== C:\Users\manuf_000\AppData\Local\Temp\BTLive.exe C:\Users\manuf_000\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-07-14 20:06 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-07-2014 01 Ran by manuf_000 at 2014-07-14 21:45:32 Running from C:\Users\manuf_000\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== µTorrent (HKCU\...\uTorrent) (Version: 3.4.2.32126 - BitTorrent Inc.) ACE Stream Media 2.0.14 (HKCU\...\ACEStream) (Version: 2.0.14 - ACE Stream Media) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.0.2.189 - Adobe Systems Incorporated) Adobe Flash Player 14 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 14.0.0.145 - Adobe Systems Incorporated) Adobe Reader XI (11.0.05) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.05 - Adobe Systems Incorporated) Amazon Cloud Player (HKCU\...\Amazon Amazon Cloud Player) (Version: 2.3.0.422 - Amazon Services LLC) Animated GIF producer 5.2 TRIAL (HKLM-x32\...\Animated GIF producer_is1) (Version: - AVLAN Design) Apple Application Support (HKLM-x32\...\{CCE825DB-347A-4004-A186-5F4A6FDD8547}) (Version: 2.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}) (Version: 6.0.1.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2021 - AVAST Software) BlueStacks Notification Center (HKLM-x32\...\{87D0541E-7EB4-44AD-8A0D-D951152020C1}) (Version: 0.7.18.921 - BlueStack Systems, Inc.) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) calibre (HKLM-x32\...\{D0AA226A-712B-4119-9B28-ABEDD936720F}) (Version: 1.26.0 - Kovid Goyal) CCleaner (HKLM\...\CCleaner) (Version: 4.13 - Piriform) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DAEMON Tools Ultra (HKLM-x32\...\DAEMON Tools Ultra) (Version: 2.0.0.0159 - Disc Soft Ltd) Filmmaker's Toolkit for Studio (HKLM-x32\...\InstallShield_{4CF172C5-F121-41FA-B0B0-0D49840BF003}) (Version: 1.00.0000 - Red Giant) Filmmaker's Toolkit for Studio (x32 Version: 1.00.0000 - Red Giant) Hidden Fotogalerie (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Free Video to JPG Converter version 5.0.27.725 (HKLM-x32\...\Free Video to JPG Converter_is1) (Version: 5.0.27.725 - DVDVideoSoft Ltd.) Galería de fotos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Galerie de photos (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 35.0.1916.153 - Google Inc.) Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google) Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden Gyazo 2.0.2 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.) High-Definition Video Playback (x32 Version: 7.1.13900.47.0 - Nero AG) Hidden ICQ 8.0 (build 6008, für aktuellen Benutzer) (HKCU\...\ICQ) (Version: 8.0.6008.0 - Mail.Ru) ICQ 8.0 Banner Remover 1.9 (HKLM-x32\...\{0A35B15C-9CCD-4C0C-BD5B-34ABF8C95813}_is1) (Version: - murb.com) ICQ Contact Revealer 1.1 (HKLM-x32\...\{5C209D68-1411-4725-8CDE-1676A85E083E}_is1) (Version: - murb.com) ICQ Link Patch 1.0 (HKLM-x32\...\{4C8458FE-8356-4D71-9A6E-A2277062F9CD}_is1) (Version: - murb.com) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.4.1441 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.1.0.1006 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.36 - Irfan Skiljan) Java 7 Update 55 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.550 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden JDownloader 0.9 (HKLM-x32\...\5513-1208-7298-9440) (Version: 0.9 - AppWork GmbH) JDownloader Packages (HKCU\...\JDownloader Packages) (Version: - ) <==== ATTENTION ManiaPlanet (HKLM-x32\...\ManiaPlanet_is1) (Version: - Nadeo) Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation) Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.3.1165.0612 - Microsoft Corporation) Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\...\{2C303EE0-A595-3543-A71A-931C7AC40EDE}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{B3B750C0-8C22-439D-B7CE-67F3ED99CC2B}) (Version: 1.20.146.0 - Microsoft) Movie Maker (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Mozilla Firefox 30.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 30.0 (x86 de)) (Version: 30.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT Redists (Version: 1.0 - Sony Creative Software Inc.) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1108.0727 - Microsoft) Hidden Multi-ICQ 1.5 (HKLM-x32\...\{5AD05333-600A-4CD8-88C6-BF22A3BE9767}_is1) (Version: - murb.com) NBA 2K14 (HKLM-x32\...\{4FE0545A-1BF3-4B9B-A044-6E1EE719E197}) (Version: 1.0.0 - 2K Sports) Nero 10 Movie ThemePack 1 (HKLM-x32\...\{43FBAB46-5969-4200-9958-1FF81FEE506F}) (Version: 10.2.10000.11.0 - Nero AG) Nero 10 Movie ThemePack Basic (x32 Version: 10.2.10000.0.0 - Nero AG) Hidden Nero BurnRights 10 (HKLM-x32\...\{943CFD7D-5336-47AF-9418-E02473A5A517}) (Version: 4.2.10500.1.102 - Nero AG) Nero BurnRights 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Control Center 10 (x32 Version: 10.2.11900.1.9 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.18400.9.0 - Nero AG) Hidden Nero CoverDesigner 10 (HKLM-x32\...\{FCF00A6E-FB58-477A-ABE9-232907105521}) (Version: 5.2.11400.11.100 - Nero AG) Nero CoverDesigner 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG) Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.11900.20.100 - Nero AG) Nero Express 10 Help (CHM) (x32 Version: 10.5.10300 - Nero AG) Hidden Nero InfoTool 10 (HKLM-x32\...\{F412B4AF-388C-4FF5-9B2F-33DB1C536953}) (Version: 7.2.10400.5.100 - Nero AG) Nero InfoTool 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero MediaHub 10 (HKLM-x32\...\{1F7FB68F-52F6-46A3-B42F-38CE46295AE5}) (Version: 1.2.13200.33.100 - Nero AG) Nero MediaHub 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{ADEF1F0B-635E-4041-B50F-A510C1B4D2C5}) (Version: 10.5.10400 - Nero AG) Nero RescueAgent 10 (HKLM-x32\...\{E337E787-CF61-4B7B-B84F-509202A54023}) (Version: 3.2.10800.9.100 - Nero AG) Nero RescueAgent 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG) Nero StartSmart 10 Help (CHM) (x32 Version: 10.5.10000 - Nero AG) Hidden Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG) Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.3 - Notepad++ Team) NVIDIA 3D Vision Controller-Treiber 310.90 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 310.90 - NVIDIA Corporation) NVIDIA 3D Vision Treiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.26.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.26.4 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.12.1031 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.3165 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.11.3 - NVIDIA Corporation) Hidden PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Photo Gallery (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Pinnacle Studio 16 - Install Manager (HKLM-x32\...\{F1886CD7-9F73-417A-92E9-7E0AB0F0E099}) (Version: 16.0.75 - Avid Technology, Inc.) Pinnacle Studio 16 - Standard Content Pack (HKLM-x32\...\{7D0F4ACC-698A-41B9-B1E2-17594988FBEF}) (Version: 16.0.0 - Avid Technology, Inc.) Pinnacle Studio 16 (HKLM-x32\...\{284BFDBC-DAC6-43EC-85A8-E1CEC0D3A114}) (Version: 16.1.0.115 - Corel Corporation) Pinnacle Video Treiber (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.030 - Pinnacle Systems) Platform (x32 Version: 1.39 - VIA Technologies, Inc.) Hidden Raccolta foto (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Rainmeter (HKLM-x32\...\Rainmeter) (Version: 3.1 beta r2286 - ) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7083 - Realtek Semiconductor Corp.) RocketDock 1.3.5 (HKLM-x32\...\RocketDock_is1) (Version: - Punk Software) Sandboxie 4.08 (64-bit) (HKLM\...\Sandboxie) (Version: 4.08 - Sandboxie Holdings, LLC) Skype™ 6.3 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.3.105 - Skype Technologies S.A.) Songbird 2.1.0 (Build 2419) (HKLM-x32\...\Songbird-release-2419) (Version: - ) SopCast 3.5.0 (HKLM-x32\...\SopCast) (Version: 3.5.0 - www.sopcast.com) TeamSpeak 3 Client (HKCU\...\TeamSpeak 3 Client) (Version: 3.0.10 - TeamSpeak Systems GmbH) TmUnitedForever Update 2010-03-15 (HKLM-x32\...\TmUnitedForever_is1) (Version: - Nadeo) Unity Web Player (HKCU\...\UnityWebPlayer) (Version: - Unity Technologies ApS) Veetle TV (HKLM-x32\...\Veetle TV) (Version: 0.9.19 - Veetle, Inc) VIA Plattform-Geräte-Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.39 - VIA Technologies, Inc.) VLC media player 2.1.0 (HKLM-x32\...\VLC media player) (Version: 2.1.0 - VideoLAN) Windows Live (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Communications Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3503.0728 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3503.0728 - Microsoft Corporation) Hidden WinRAR 5.00 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) XMedia Recode Version 3.1.3.7 (HKLM-x32\...\{DDA3C325-47B2-4730-9672-BF3771C08799}_is1) (Version: 3.1.3.7 - XMedia Recode) Yet Another Cleaner! (HKLM-x32\...\iSafe) (Version: - ELEX DO BRASIL PARTICIPAÇÕES LTDA) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask Task: {082F9E1D-1494-4C32-AF2C-BE29605897DF} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd) Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {11EC7259-34BE-4793-9007-44B789C3C3FE} - \EPUpdater No Task File <==== ATTENTION Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {26B18472-31FD-4175-998C-C519C33949DC} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation) Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation) Task: {3C76346A-E78C-4ED6-A26E-79E2B35FA309} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance Task: {4EE5589C-2604-4FDD-9C39-830AF15B8A8B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-07] (Google Inc.) Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task Task: {70158B86-722F-4DB6-99C8-828F52EB6C85} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-2245968268-1096486666-1822319797-1002 => %localappdata%\Microsoft\SkyDrive\SkyDrive.exe Task: {718618C5-FD3C-443A-88AE-8DE8791B5F49} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-07-08] (Adobe Systems Incorporated) Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {7CD80C85-3B83-42FB-8387-00892D67C958} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-14] (AVAST Software) Task: {800C022D-5F8D-44EF-A3F5-A54A118E8C68} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work Task: {A11EF264-3C4D-4F38-9416-5E0AF038CE7F} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-manufarago@googlemail.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2013-06-03] (Adobe Systems Incorporated) Task: {A4EC8CA2-54EA-47E7-AC5B-C163C5411B53} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload Task: {A66C563C-4588-4022-9900-4DFA5DA1B544} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv Task: {B7E20EE9-A592-46EE-8304-569CC9578138} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {CE989AD4-7F6C-4F3E-8912-0BCB268D4442} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-12-07] (Google Inc.) Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization Task: {DF2925B5-53DB-4C14-B645-6CEDBDEF4822} - \AmiUpdXp No Task File <==== ATTENTION Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE Task: {F13DC800-97C5-4604-A619-4C3FE5A7C172} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2014-07-10] (Microsoft Corporation) Task: {F19F921C-EA4C-42AE-9FEB-584F88225342} - \Software Updater No Task File <==== ATTENTION Task: {FE3177B2-AFC3-47BF-8AF6-75E49AAC92D6} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation) Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-10 08:24 - 2013-10-23 10:20 - 00102176 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2011-06-21 08:42 - 2011-06-21 08:42 - 00034304 _____ () C:\WINDOWS\System32\sst3cl6.dll 2011-06-21 03:23 - 2011-06-21 03:23 - 00826880 _____ () C:\WINDOWS\system32\spool\DRIVERS\x64\3\sst3cdu.dll 2014-07-14 16:41 - 2014-07-14 16:41 - 00330544 _____ () C:\Program Files (x86)\Isis\isis.exe 2014-07-14 20:18 - 2014-07-11 14:22 - 02228896 _____ () C:\Program Files (x86)\iSafe\ipcdl.exe 2013-06-20 00:45 - 2013-06-20 00:45 - 03317616 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll 2014-07-14 18:35 - 2014-07-14 18:35 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll 2014-07-14 20:21 - 2014-07-14 20:21 - 02792960 _____ () C:\Program Files\AVAST Software\Avast\defs\14071401\algo.dll 2012-11-28 15:13 - 2012-11-28 15:13 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-11-28 15:13 - 2012-11-28 15:13 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2014-07-14 20:18 - 2014-07-11 14:22 - 00092320 _____ () C:\Program Files (x86)\iSafe\curlpp.dll 2014-07-14 20:18 - 2014-07-11 14:22 - 00185640 _____ () C:\Program Files (x86)\iSafe\libpng.dll 2014-07-14 20:18 - 2014-07-11 14:22 - 00065696 _____ () C:\Program Files (x86)\iSafe\zlib1.dll 2014-07-14 18:35 - 2014-07-14 18:35 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-04-04 10:25 - 2014-04-04 10:25 - 00102400 _____ () C:\Program Files (x86)\Isis\nfapi.dll 2014-06-05 06:41 - 2014-06-05 06:41 - 00331776 _____ () C:\Program Files (x86)\Isis\ProtocolFilters.dll 2014-02-13 17:06 - 2014-02-13 17:06 - 00172544 _____ () C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IsdiInterop\a6d333ccc38ce632f86376633ee2ae96\IsdiInterop.ni.dll 2012-10-16 12:01 - 2012-02-01 16:25 - 00059904 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll 2012-10-16 12:02 - 2012-03-07 01:27 - 01198872 ____R () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll 2014-07-14 20:37 - 2014-06-05 15:58 - 00716616 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libglesv2.dll 2014-07-14 20:37 - 2014-06-05 15:58 - 00126280 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\libegl.dll 2014-07-14 20:37 - 2014-06-05 15:58 - 04217672 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\pdf.dll 2014-07-14 20:37 - 2014-06-05 15:58 - 00414536 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll 2014-07-14 20:37 - 2014-06-05 15:58 - 01732424 _____ () C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\ffmpegsumo.dll 2014-07-11 20:34 - 2014-07-08 08:18 - 14663856 _____ () C:\Users\manuf_000\AppData\Local\Google\Chrome\User Data\PepperFlash\14.0.0.145\pepflashplayer.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00840192 _____ () C:\Program Files (x86)\Songbird\xulrunner\js3250.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00014848 _____ () C:\Program Files (x86)\Songbird\components\sbThreadPoolService.dll 2012-10-25 23:42 - 2013-02-23 23:49 - 00053248 _____ () C:\Program Files (x86)\Songbird\extensions\philips-addon-manager@songbirdnest.com\platform\WINNT_x86-msvc\components\phAddonManager.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00798720 _____ () C:\Program Files (x86)\Songbird\components\sbLocalDatabaseLibrary.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00122880 _____ () C:\Program Files (x86)\Songbird\components\sbDeviceFirmwareUpdater.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00548864 _____ () C:\Program Files (x86)\Songbird\components\sbDeviceManager2.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00180224 _____ () C:\Program Files (x86)\Songbird\components\sbLibraryManager.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00126976 _____ () C:\Program Files (x86)\Songbird\components\sbMediaExport.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00217088 _____ () C:\Program Files (x86)\Songbird\components\sbMediacoreManager.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00036864 _____ () C:\Program Files (x86)\Songbird\components\sbDeviceManager.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00061440 _____ () C:\Program Files (x86)\Songbird\components\sbPlayQueueService.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00013312 _____ () C:\Program Files (x86)\Songbird\components\sbdataremote.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00118784 _____ () C:\Program Files (x86)\Songbird\components\sbPlaybackHistoryService.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00065536 _____ () C:\Program Files (x86)\Songbird\components\sbSQLBuilder.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00065536 _____ () C:\Program Files (x86)\Songbird\components\sbPlaylistCommands.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00069632 _____ () C:\Program Files (x86)\Songbird\components\sbIntegration.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00106496 _____ () C:\Program Files (x86)\Songbird\components\sbWatchFolderService.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00114688 _____ () C:\Program Files (x86)\Songbird\components\sbWin32FileSystemEvents.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00118784 _____ () C:\Program Files (x86)\Songbird\components\sbAlbumArt.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00013824 _____ () C:\Program Files (x86)\Songbird\components\sbDirectoryProvider.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00016896 _____ () C:\Program Files (x86)\Songbird\components\sbUpdate.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00065536 _____ () C:\Program Files (x86)\Songbird\components\sbMediaItemDownloadService.dll 2012-10-25 23:45 - 2013-02-23 23:49 - 00013824 _____ () C:\Program Files (x86)\Songbird\extensions\sharing@songbirdnest.com\platform\WINNT_x86-msvc\components\sbSharingStub.dll 2012-10-25 23:45 - 2013-02-23 23:49 - 00049152 _____ () C:\Program Files (x86)\Songbird\extensions\sharing@songbirdnest.com\platform\WINNT_x86-msvc\lib\libdlna_sb.dll 2012-10-25 23:45 - 2013-02-23 23:49 - 01454080 _____ () C:\Program Files (x86)\Songbird\extensions\sharing@songbirdnest.com\platform\WINNT_x86-msvc\lib\sbSharing.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00045056 _____ () C:\Program Files (x86)\Songbird\components\sbIntl.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00045056 _____ () C:\Program Files (x86)\Songbird\components\sbTemporaryFileService.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00053248 _____ () C:\Program Files (x86)\Songbird\components\sbWindowWatcher.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00053248 _____ () C:\Program Files (x86)\Songbird\components\sbxpcom.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00013312 _____ () C:\Program Files (x86)\Songbird\components\sbGStreamerStub.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00034304 _____ () C:\Program Files (x86)\Songbird\lib\ogg-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00106496 _____ () C:\Program Files (x86)\Songbird\lib\theoradec-1.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00262144 _____ () C:\Program Files (x86)\Songbird\lib\theoraenc-1.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00233472 _____ () C:\Program Files (x86)\Songbird\lib\vorbis-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 01187840 _____ () C:\Program Files (x86)\Songbird\lib\vorbisenc-2.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00046080 _____ () C:\Program Files (x86)\Songbird\lib\vorbisfile-3.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00258048 _____ () C:\Program Files (x86)\Songbird\lib\FLAC-8.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00335872 _____ () C:\Program Files (x86)\Songbird\lib\jpeg-7.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 01048576 _____ () C:\Program Files (x86)\Songbird\lib\gstreamer-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00352256 _____ () C:\Program Files (x86)\Songbird\lib\gstbase-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00038912 _____ () C:\Program Files (x86)\Songbird\lib\gstdataprotocol-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00188416 _____ () C:\Program Files (x86)\Songbird\lib\gstcontroller-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00094208 _____ () C:\Program Files (x86)\Songbird\lib\gstinterfaces-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00200704 _____ () C:\Program Files (x86)\Songbird\lib\gstaudio-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00126976 _____ () C:\Program Files (x86)\Songbird\lib\gsttag-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00055296 _____ () C:\Program Files (x86)\Songbird\lib\gstcdda-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00081920 _____ () C:\Program Files (x86)\Songbird\lib\gstfft-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00021504 _____ () C:\Program Files (x86)\Songbird\lib\gstnetbuffer-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00081920 _____ () C:\Program Files (x86)\Songbird\lib\gstpbutils-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00086016 _____ () C:\Program Files (x86)\Songbird\lib\gstriff-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00126976 _____ () C:\Program Files (x86)\Songbird\lib\gstrtp-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00131072 _____ () C:\Program Files (x86)\Songbird\lib\gstrtsp-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00042496 _____ () C:\Program Files (x86)\Songbird\lib\gstsdp-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00057344 _____ () C:\Program Files (x86)\Songbird\lib\gstvideo-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00081920 _____ () C:\Program Files (x86)\Songbird\lib\gstapp-0.10-0.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00364544 _____ () C:\Program Files (x86)\Songbird\lib\sbGStreamerMediacore.dll 2013-02-23 23:49 - 2013-01-28 11:02 - 00282624 _____ () C:\Users\manuf_000\AppData\Roaming\Songbird2\Profiles\kcrn9w2w.default\extensions\windowsmedia@songbirdnest.com\platform\WINNT_x86-msvc\components\sbWindowsMediacore.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00602112 _____ () C:\Program Files (x86)\Songbird\components\sbDBEngine.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00053248 _____ () C:\Program Files (x86)\Songbird\components\sbMozVariant.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00290816 _____ () C:\Program Files (x86)\Songbird\components\sbProperties.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00017920 _____ () C:\Program Files (x86)\Songbird\components\sbIdentityServiceComponent.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00122880 _____ () C:\Program Files (x86)\Songbird\components\sbDownloadDevice.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00159744 _____ () C:\Program Files (x86)\Songbird\components\sbiTunesMediaImport.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00057344 _____ () C:\Program Files (x86)\Songbird\components\sbStrings.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00606208 _____ () C:\Program Files (x86)\Songbird\components\sbCDDevice.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00015872 _____ () C:\Program Files (x86)\Songbird\components\sbMediaSniffer.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00139264 _____ () C:\Program Files (x86)\Songbird\components\sbMetadataModule.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00023552 _____ () C:\Program Files (x86)\Songbird\components\sbFileUtils.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00041472 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstequalizer.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00062976 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstreplaygain.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00033280 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstvolume.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00303104 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstplaybin.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00811008 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstdirectsoundsink.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00102400 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstaudioconvert.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00176128 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstdshowvideosink.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00151552 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstdecodebin2.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00221184 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstcoreelements.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00094208 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gsttypefindfunctions.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00022528 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstid3demux.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00102400 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstmpegaudioparse.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00027648 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstacmmp3dec.dll 2012-10-25 23:57 - 2013-02-23 23:49 - 00106496 _____ () C:\Program Files (x86)\Songbird\gst-plugins\gstaudioresample.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\manuf_000\SkyDrive:ms-properties ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== MSCONFIG/TASK MANAGER disabled items ========= HKLM\...\StartupApproved\Run32: => "APSDaemon" HKLM\...\StartupApproved\Run32: => "BlueStacks Agent" HKLM\...\StartupApproved\Run32: => "CrashMon" HKCU\...\StartupApproved\StartupFolder: => "Rainmeter.lnk" HKCU\...\StartupApproved\Run: => "ACEStream" HKCU\...\StartupApproved\Run: => "Amazon Cloud Player" HKCU\...\StartupApproved\Run: => "DAEMON Tools Ultra Agent" HKCU\...\StartupApproved\Run: => "SandboxieControl" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2014-07-14 20:28:51.904 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume1\Program Files (x86)\iSafe\iSafeSrvMon64.dll that did not meet the Windows signing level requirements. Date: 2014-04-01 23:59:08.466 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\ProgramData\Microsoft\Windows Defender\Definition Updates\{B647BC9A-4438-466E-A400-6C816B136FFB}\mpengine.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2014-04-01 23:59:08.065 Description: Code Integrity determined that a process (\Device\HarddiskVolume1\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume1\ProgramData\Microsoft\Windows Defender\Definition Updates\{1D891E58-5CED-4CB1-AF8E-5179FB10FA6E}\mpengine.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== Percentage of memory in use: 30% Total physical RAM: 8125.73 MB Available physical RAM: 5646.8 MB Total Pagefile: 9405.73 MB Available Pagefile: 6473.34 MB Total Virtual: 131072 MB Available Virtual: 131071.79 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:55.9 GB) (Free:6.75 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:98.08 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 56 GB) (Disk ID: 7E46533D) Partition 1: (Active) - (Size=56 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: F5C62B1B) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
15.07.2014, 19:26 | #4 |
/// the machine /// TB-Ausbilder | Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw) Adware & Co. deinstallieren
Solltest Du ein Programm nicht finden oder nicht deinstallieren können, mache bitte mit dem nächsten Schritt weiter: Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.07.2014, 20:14 | #5 |
| Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw) um das ganze möglicherweise abzukürzen.. ich hab mittlerweile mit 2 anderen Leuten geschrieben die genau das gleiche Problem seit gestern haben. Die haben im task-manager die "isis.exe" geschlossen und als autostart entfernt. das hat auch bei mir geholfen und das problem sofort behoben. als ich die logfiles gemacht habe gestern war die isis.exe allerdings deaktiviert, wohl durch das von mir erwähnte programm "Junkware Removal Tool". deswegen wahrscheinlich nichts davon zu sehen im logfile. soll ich jetzt trotzdem die verschiedenen schritte noch durchführen oder gibt es was anderes was ich machen kann ? |
16.07.2014, 18:32 | #6 |
/// the machine /// TB-Ausbilder | Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw) Der Rechner ist trotzdem voll mit Adware, also ich würd obiges ja machen
__________________ --> Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw) |
Themen zu Plötzlich viele Probleme (cdn.cloudwm.com, SSL Verbindungsfehler usw) |
antivirus, avast, ccleaner, firefox, forum, free, funktioniert, gen, gesucht, google, internet, junkware, nutzen, ordner, plötzlich, probleme, programm, programme, seite, suchmaschine, tool, verbindung, verbindungsfehler, viren, websites, win, öffnet |