![]() |
|
Plagegeister aller Art und deren Bekämpfung: neuer Laptop Win 8.1 total langsamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #5 |
![]() | ![]() neuer Laptop Win 8.1 total langsamCode:
ATTFilter # AdwCleaner v4.109 - Bericht erstellt am 25/01/2015 um 16:38:37 # Aktualisiert 24/01/2015 von Xplode # Database : 2015-01-24.3 [Local] # Betriebssystem : Windows 8.1 (64 bits) # Benutzername : Arbeit Daniel - DANIEL # Gestartet von : C:\Users\Arbeit Daniel\AppData\Local\Microsoft\Windows\INetCache\IE\LFGU6VHS\AdwCleaner_4.109.exe # Option : Suchen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gefunden : C:\END Datei Gefunden : C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage Datei Gefunden : C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal Datei Gefunden : C:\Windows\System32\abengine64.dll Ordner Gefunden : C:\Program Files (x86)\BWSRappSev2 Ordner Gefunden : C:\Program Files (x86)\globalUpdate Ordner Gefunden : C:\ProgramData\186fef6e00000659 Ordner Gefunden : C:\ProgramData\43a438fc00001e7f Ordner Gefunden : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip Ordner Gefunden : C:\Users\Arbeit Daniel\AppData\Local\globalUpdate Ordner Gefunden : C:\Users\Arbeit Daniel\AppData\Local\Pro_PC_Cleaner Ordner Gefunden : C:\Users\Arbeit Daniel\AppData\Roaming\InetStat Ordner Gefunden : C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat Ordner Gefunden : C:\Users\Arbeit Daniel\Documents\Optimizer Pro Ordner Gefunden : C:\Users\Arbeit Daniel\Documents\ProPCCleaner Ordner Gefunden : C:\Users\ARBEIT~1\AppData\Local\Temp\CommonShare ***** [ Tasks ] ***** Task Gefunden : ProPCCleaner_Start Task Gefunden : ProPCCleaner_Popup ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gefunden : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gefunden : HKCU\Software\AppDataLow\Software\BWSRappSev2 Schlüssel Gefunden : HKCU\Software\Classes\Applications\inetstat.exe Schlüssel Gefunden : HKCU\Software\Classes\pokki Schlüssel Gefunden : HKCU\Software\GAMESDESKTOP Schlüssel Gefunden : HKCU\Software\GlobalUpdate Schlüssel Gefunden : HKCU\Software\InetStat Schlüssel Gefunden : HKCU\Software\InstalledBrowserExtensions Schlüssel Gefunden : HKCU\Software\MICROSOFT\INTERNET EXPLORER\DOMSTORAGE\superfish.com Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\www.superfish.com Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DF9F6E42-A85C-42CC-82C6-BB102DEF23E1} Schlüssel Gefunden : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611991117} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611991117} Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki Schlüssel Gefunden : HKCU\Software\Optimizer Pro Schlüssel Gefunden : HKCU\Software\Pokki Schlüssel Gefunden : HKCU\Software\ProPCCleanerLanguage Schlüssel Gefunden : HKCU\Software\Super Optimizer Schlüssel Gefunden : HKCU\Software\Tutorials Schlüssel Gefunden : HKCU\Software\Wnkey Schlüssel Gefunden : [x64] HKCU\Software\GAMESDESKTOP Schlüssel Gefunden : [x64] HKCU\Software\GlobalUpdate Schlüssel Gefunden : [x64] HKCU\Software\InetStat Schlüssel Gefunden : [x64] HKCU\Software\InstalledBrowserExtensions Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{DF9F6E42-A85C-42CC-82C6-BB102DEF23E1} Schlüssel Gefunden : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} Schlüssel Gefunden : [x64] HKCU\Software\Optimizer Pro Schlüssel Gefunden : [x64] HKCU\Software\Pokki Schlüssel Gefunden : [x64] HKCU\Software\ProPCCleanerLanguage Schlüssel Gefunden : [x64] HKCU\Software\Super Optimizer Schlüssel Gefunden : [x64] HKCU\Software\Tutorials Schlüssel Gefunden : [x64] HKCU\Software\Wnkey Schlüssel Gefunden : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gefunden : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} Schlüssel Gefunden : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C} Schlüssel Gefunden : HKLM\SOFTWARE\BWSRappSev2 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{02A96331-0CA6-40E2-A87D-C224601985EB} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611991117} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622992217} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdate.OneClickProcessLauncherMachine.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoCreateAsync.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreClass.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CoreMachineClass.1 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.CredentialDialogMachine.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachine.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassMachineFallback.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.OnDemandCOMClassSvc.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.ProcessLauncher.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3COMClassService.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachine.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebMachineFallback.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc Schlüssel Gefunden : HKLM\SOFTWARE\Classes\globalUpdateUpdate.Update3WebSvc.1.0 Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655995517} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666996617} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644994417} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440644994417} Schlüssel Gefunden : HKLM\SOFTWARE\GlobalUpdate Schlüssel Gefunden : HKLM\SOFTWARE\InstalledBrowserExtensions Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2d50b5ca-fe9d-4541-9d77-3d5b61048592} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ae85ed90-359d-4da3-b794-6936929b7340} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611991117} Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BWSRappSev2 Schlüssel Gefunden : HKLM\SOFTWARE\SPPDCOM Schlüssel Gefunden : HKLM\SOFTWARE\SupDp Schlüssel Gefunden : HKLM\SOFTWARE\Tutorials Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110611991117} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220622992217} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550655995517} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660666996617} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{2d50b5ca-fe9d-4541-9d77-3d5b61048592} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ae85ed90-359d-4da3-b794-6936929b7340} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611991117} Wert Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki] ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17037 Einstellung Gefunden : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL] - hxxp://tikotin.com -\\ Google Chrome v40.0.2214.91 [C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=ST500LT012-1DG142_W3P8REZNXXXXW3P8REZN&ts=1422051337&type=default&q={searchTerms} [C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://isearch.omiga-plus.com/web/?utm_source=b&utm_medium=tugs&utm_campaign=install_ie&utm_content=ds&from=tugs&uid=ST500LT012-1DG142_W3P8REZNXXXXW3P8REZN&ts=1422051337&type=default&q={searchTerms} [C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330130&octid=EB_ORIGINAL_CTID&ISID=MAA266058-6AD7-4DEC-B67D-0080AD9A963B&SearchSource=58&CUI=&UM=8&UP=SPD47E5FB2-76FE-4965-B099-7216033A1130&q={searchTerms}&SSPV= [C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Web data] - Gefunden [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3330130&octid=EB_ORIGINAL_CTID&ISID=MAA266058-6AD7-4DEC-B67D-0080AD9A963B&SearchSource=58&CUI=&UM=8&UP=SPD47E5FB2-76FE-4965-B099-7216033A1130&q={searchTerms}&SSPV= ************************* AdwCleaner[R0].txt - [13134 octets] - [25/01/2015 16:38:37] ########## EOF - C:\AdwCleaner\AdwCleaner[R0].txt - [13195 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.1 (12.28.2014:1) OS: Windows 8.1 x64 Ran by Arbeit Daniel on 25.01.2015 at 16:46:59,15 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110611991117} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220622992217} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550655995517} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660666996617} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440644994417} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{11111111-1111-1111-1111-110611991117} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220622992217} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{55555555-5555-5555-5555-550655995517} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660666996617} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644994417} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550655995517} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660666996617} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440644994417} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110611991117} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110611991117} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{55555555-5555-5555-5555-550655995517} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660666996617} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\TypeLib\{44444444-4444-4444-4444-440644994417} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110611991117} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2023ECEC-E06A-4372-A1C7-0B49F9E0FFF0} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{DF9F6E42-A85C-42CC-82C6-BB102DEF23E1} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E733165D-CBCF-4FDA-883E-ADEF965B476C} ~~~ Files Successfully deleted: [File] "C:\Users\Arbeit Daniel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage" Successfully deleted: [File] "C:\Users\Arbeit Daniel\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal" ~~~ Folders Successfully deleted: [Folder] "C:\Users\Arbeit Daniel\appdata\local\globalupdate" Successfully deleted: [Folder] "C:\Users\Arbeit Daniel\appdata\local\pro_pc_cleaner" Successfully deleted: [Folder] "C:\Program Files (x86)\globalupdate" Successfully deleted: [Folder] "C:\Users\Arbeit Daniel\documents\optimizer pro" Successfully deleted: [Folder] "C:\Users\Arbeit Daniel\documents\propccleaner" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 25.01.2015 at 16:49:53,51 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-01-2015 01 Ran by Arbeit Daniel (administrator) on DANIEL on 25-01-2015 17:05:16 Running from C:\Users\Arbeit Daniel\AppData\Local\Microsoft\Windows\INetCache\IE\4GC2J6PJ Loaded Profiles: Arbeit Daniel (Available profiles: Arbeit Daniel) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUicnt.exe (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe (Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QuickAccess.exe (Pokki) C:\Users\Arbeit Daniel\AppData\Local\Pokki\Engine\HostAppService.exe (Pokki) C:\Users\Arbeit Daniel\AppData\Local\Pokki\Engine\HostAppServiceUpdater.exe (Pokki) C:\Users\Arbeit Daniel\AppData\Local\Pokki\Engine\HostAppService.exe (Pokki) C:\Users\Arbeit Daniel\AppData\Local\Pokki\Engine\StartMenuIndexer.exe (TODO: <Company name>) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe (McAfee, Inc.) C:\Program Files\mcafee\vul\McVulCtr.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (BroServix+2.3) C:\Program Files (x86)\BWSRappSev2\BWSRappSev2-bg.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-18] (Realtek Semiconductor) HKLM\...\Run: [3D BubbleSound] => C:\Program Files\BubbleSound\3D BubbleSound.exe [14115328 2015-01-09] (zik.mu) HKLM-x32\...\Run: [Adobe ARM] => c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-07-24] (McAfee, Inc.) HKU\S-1-5-21-372149687-12892241-2324643792-1001\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.) GroupPolicy: Group Policy on Chrome detected <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\S-1-5-21-372149687-12892241-2324643792-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://tikotin.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKU\S-1-5-21-372149687-12892241-2324643792-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKU\S-1-5-21-372149687-12892241-2324643792-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search BHO: BWSRappSev2 -> {11111111-1111-1111-1111-110611991117} -> C:\Program Files (x86)\BWSRappSev2\BWSRappSev2-bho64.dll (BroServix+2.3) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\siteadvisor\McIEPlg.dll (McAfee, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\mcsniepl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) Winsock: Catalog9 01 C:\Windows\system32\abengine.dll File Not found () Winsock: Catalog9 02 C:\Windows\system32\abengine.dll File Not found () Winsock: Catalog9 03 C:\Windows\system32\abengine.dll File Not found () Winsock: Catalog9 04 C:\Windows\system32\abengine.dll File Not found () Winsock: Catalog9 16 C:\Windows\system32\abengine.dll File Not found () Winsock: Catalog9-x64 01 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 02 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 03 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 04 C:\Windows\system32\abengine64.dll [370880] (Abengine) Winsock: Catalog9-x64 16 C:\Windows\system32\abengine64.dll [370880] (Abengine) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 FireFox: ======== FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\npmcsnffpl64.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\npmcsnffpl.dll () FF Plugin-x32: @mcafee.com/SAFFPlugin -> C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin-x32: Adobe Reader -> c:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2014-05-16] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-05-16] FF HKU\S-1-5-21-372149687-12892241-2324643792-1001\...\Firefox\Extensions: [{7DEBE74A-F60E-1010-4430-598EAAAF698D}] - C:\Program Files (x86)\ver8SpeedChecker\186.xpi Chrome: ======= CHR HomePage: Default -> hxxp://www.google.de/ CHR StartupUrls: Default -> "hxxp://www.trovi.com/?gd=&ctid=CT3330130&octid=EB_ORIGINAL_CTID&ISID=MAA266058-6AD7-4DEC-B67D-0080AD9A963B&SearchSource=55&CUI=&UM=8&UP=SPD47E5FB2-76FE-4965-B099-7216033A1130&SSPV=" CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-01-23] CHR Extension: (Google Docs) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-01-23] CHR Extension: (Google Drive) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-23] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-01-24] CHR Extension: (YouTube) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-23] CHR Extension: (Adblock Plus) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-01-24] CHR Extension: (Google Search) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-23] CHR Extension: (Google Sheets) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-01-23] CHR Extension: (SiteAdvisor) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-01-23] CHR Extension: (AdBlock) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-01-24] CHR Extension: (Google Wallet) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-23] CHR Extension: (Gmail) - C:\Users\Arbeit Daniel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-23] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-07-21] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2013-11-14] (Broadcom Corporation.) R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2713856 2014-12-19] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573544 2014-03-21] (Acer Incorporated) R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [235008 2013-07-16] (TODO: <Company name>) [File not signed] R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-18] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation) R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [459496 2014-01-18] (Acer Incorporate) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [175464 2013-07-24] (McAfee, Inc.) S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-25] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-07-06] (McAfee, Inc.) R2 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1017016 2013-09-20] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-08-07] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [182752 2013-08-07] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-09-30] (McAfee, Inc.) R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457960 2014-03-04] (Acer Incorporate) R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] () R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-03-04] (Acer Incorporate) R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-24] (acer) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-09-25] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-09-25] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-11-14] (Broadcom Corporation.) R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7549616 2014-02-25] (Broadcom Corporation) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-08-07] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197264 2012-05-28] (McAfee, Inc.) R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [99320 2013-10-03] (Intel Corporation) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-01-24] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation) R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179664 2013-08-07] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [310224 2013-08-07] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69264 2013-08-07] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519064 2013-08-07] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [776168 2013-08-07] (McAfee, Inc.) R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [390552 2013-09-20] (McAfee, Inc.) S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [95984 2013-09-20] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343568 2013-08-07] (McAfee, Inc.) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated) R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [466136 2014-01-14] (Realsil Semiconductor Corporation) R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-19] (Synaptics Incorporated) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-09-25] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-25 16:56 - 2015-01-25 16:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2015-01-25 16:49 - 2015-01-25 16:49 - 00004566 _____ () C:\Users\Arbeit Daniel\Desktop\JRT.txt 2015-01-25 16:46 - 2015-01-25 16:46 - 00000000 ____D () C:\Windows\ERUNT 2015-01-25 14:30 - 2015-01-25 16:39 - 00000000 ____D () C:\AdwCleaner 2015-01-24 19:36 - 2015-01-24 19:37 - 00030357 _____ () C:\Users\Arbeit Daniel\Downloads\Addition.txt 2015-01-24 19:35 - 2015-01-25 17:05 - 00000000 ____D () C:\FRST 2015-01-24 19:35 - 2015-01-24 19:37 - 00039811 _____ () C:\Users\Arbeit Daniel\Downloads\FRST.txt 2015-01-24 19:35 - 2015-01-24 19:35 - 02129920 _____ (Farbar) C:\Users\Arbeit Daniel\Downloads\FRST64 (1).exe 2015-01-24 19:34 - 2015-01-24 19:34 - 02129920 _____ (Farbar) C:\Users\Arbeit Daniel\Downloads\FRST64.exe 2015-01-24 17:22 - 2015-01-24 17:22 - 00000000 ____D () C:\ProgramData\186fef6e00000659 2015-01-24 17:21 - 2015-01-24 17:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2015-01-24 17:16 - 2015-01-24 17:16 - 00000306 __RSH () C:\ProgramData\ntuser.pol 2015-01-24 17:14 - 2015-01-24 17:14 - 00021976 _____ () C:\Windows\system32\Drivers\SPPD.sys 2015-01-24 13:33 - 2015-01-24 17:24 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\Windows Live 2015-01-24 13:32 - 2015-01-24 13:32 - 01239752 _____ (Microsoft Corporation) C:\Users\Arbeit Daniel\Downloads\wlsetup-web.exe 2015-01-24 13:26 - 2015-01-24 17:16 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-24 13:26 - 2015-01-24 13:26 - 00001114 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-24 13:26 - 2015-01-24 13:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-24 13:25 - 2015-01-24 13:26 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-24 13:25 - 2015-01-24 13:25 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-24 13:25 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-24 13:25 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-24 13:25 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-24 13:24 - 2015-01-24 13:24 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Arbeit Daniel\Downloads\mbam-setup-2.0.4.1028.exe 2015-01-24 13:14 - 2015-01-24 13:14 - 00000000 ____D () C:\ProgramData\43a438fc00001e7f 2015-01-24 13:12 - 2015-01-24 13:12 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BubbleSound 1.0 2015-01-24 13:12 - 2015-01-24 13:12 - 00000000 ____D () C:\Program Files\BubbleSound 2015-01-24 13:10 - 2015-01-24 13:10 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\Acer Aspire R7 Tutorial 2015-01-24 13:08 - 2015-01-24 17:14 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Roaming\InetStat 2015-01-24 13:08 - 2015-01-24 13:08 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\InetStat 2015-01-24 13:04 - 2014-12-05 00:09 - 00370880 _____ (Abengine) C:\Windows\system32\abengine64.dll 2015-01-24 13:03 - 2015-01-24 13:03 - 00000002 _____ () C:\END 2015-01-24 13:02 - 2015-01-24 17:15 - 00001384 _____ () C:\Windows\Tasks\SWRDAM.job 2015-01-24 13:02 - 2015-01-24 13:02 - 00004402 _____ () C:\Windows\System32\Tasks\SWRDAM 2015-01-24 13:02 - 2015-01-24 13:02 - 00000000 ____D () C:\Program Files (x86)\99d5089f-8116-4850-8c55-0f51a9c108f8 2015-01-24 13:01 - 2015-01-24 17:14 - 00000000 ____D () C:\ProgramData\TPMRZi 2015-01-23 23:18 - 2015-01-25 15:29 - 00001150 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-23 23:18 - 2015-01-24 17:16 - 00001146 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-23 23:18 - 2015-01-23 23:24 - 00004122 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-01-23 23:18 - 2015-01-23 23:24 - 00003886 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-01-23 23:18 - 2015-01-23 23:18 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\Google 2015-01-23 23:18 - 2015-01-23 23:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2015-01-23 23:18 - 2015-01-23 23:18 - 00000000 ____D () C:\Program Files (x86)\Google 2015-01-23 23:16 - 2015-01-24 14:00 - 00000000 ___HD () C:\Users\Public\Temp 2015-01-23 23:15 - 2015-01-23 23:15 - 00003472 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Popup 2015-01-23 23:15 - 2015-01-23 23:15 - 00003208 _____ () C:\Windows\System32\Tasks\ProPCCleaner_Start 2015-01-23 23:14 - 2015-01-25 16:40 - 00001384 _____ () C:\Windows\Tasks\WDXJHF.job 2015-01-23 23:14 - 2015-01-24 17:58 - 00001384 _____ () C:\Windows\Tasks\QKTMVX.job 2015-01-23 23:14 - 2015-01-24 17:12 - 00000000 ____D () C:\Program Files (x86)\BWSRappSev2 2015-01-23 23:14 - 2015-01-23 23:14 - 01878504 _____ (BroServix+2.3) C:\Users\Arbeit Daniel\AppData\Roaming\WDXJHF.exe 2015-01-23 23:14 - 2015-01-23 23:14 - 00004402 _____ () C:\Windows\System32\Tasks\WDXJHF 2015-01-23 23:14 - 2015-01-23 23:14 - 00004402 _____ () C:\Windows\System32\Tasks\QKTMVX 2015-01-23 23:13 - 2015-01-23 23:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip 2015-01-23 23:11 - 2015-01-25 16:53 - 00003592 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-372149687-12892241-2324643792-1001 2015-01-23 23:11 - 2015-01-25 14:27 - 00003954 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0236F925-95AD-4D52-86AE-38EFBEF32D33} 2015-01-23 23:11 - 2015-01-23 23:11 - 00000000 __SHD () C:\Users\Arbeit Daniel\AppData\Local\EmieUserList 2015-01-23 23:11 - 2015-01-23 23:11 - 00000000 __SHD () C:\Users\Arbeit Daniel\AppData\Local\EmieSiteList 2015-01-23 23:11 - 2015-01-23 23:11 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Roaming\Macromedia 2015-01-23 23:09 - 2015-01-24 13:01 - 00002163 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk 2015-01-23 23:09 - 2015-01-23 23:09 - 00000000 ____D () C:\Users\Public\Pokki 2015-01-23 23:09 - 2015-01-23 23:09 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\AOP SDK 2015-01-23 23:08 - 2015-01-24 17:17 - 00002334 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk 2015-01-23 23:07 - 2015-01-23 23:08 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\clear.fi 2015-01-23 23:07 - 2015-01-23 23:07 - 00000000 ____D () C:\Users\Arbeit Daniel\PicStream 2015-01-23 23:06 - 2015-01-23 23:06 - 00001272 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk 2015-01-23 23:06 - 2015-01-23 23:06 - 00000000 ____D () C:\Windows\System32\Tasks\WPD 2015-01-23 23:06 - 2015-01-23 23:06 - 00000000 ____D () C:\ProgramData\OEM_YAHOO 2015-01-23 23:05 - 2015-01-25 15:02 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\Packages 2015-01-23 23:05 - 2015-01-23 23:38 - 00001450 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2015-01-23 23:05 - 2015-01-23 23:05 - 00000180 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2015-01-23 23:05 - 2015-01-23 23:05 - 00000020 ___SH () C:\Users\Arbeit Daniel\ntuser.ini 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Vorlagen 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Startmenü 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Netzwerkumgebung 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Lokale Einstellungen 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Eigene Dateien 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Druckumgebung 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Documents\Eigene Musik 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Documents\Eigene Bilder 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\AppData\Local\Verlauf 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\AppData\Local\Anwendungsdaten 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 _SHDL () C:\Users\Arbeit Daniel\Anwendungsdaten 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Roaming\Adobe 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\VirtualStore 2015-01-23 23:05 - 2015-01-23 23:05 - 00000000 ____D () C:\Program Files\Accessory Store 2015-01-23 23:04 - 2015-01-25 14:24 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Local\Pokki 2015-01-23 23:04 - 2015-01-23 23:07 - 00000000 ____D () C:\Users\Arbeit Daniel 2015-01-23 23:04 - 2014-09-25 10:54 - 00000000 ___RD () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools 2015-01-23 23:04 - 2014-03-18 11:33 - 00000000 ___RD () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility 2015-01-23 23:04 - 2014-03-18 11:13 - 00000369 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk 2015-01-23 23:04 - 2014-03-18 11:13 - 00000369 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk 2015-01-23 23:04 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-01-23 23:04 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\Arbeit Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-01-23 23:01 - 2015-01-25 17:05 - 01619561 _____ () C:\Windows\WindowsUpdate.log 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Vorlagen 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Startmenü 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Druckumgebung 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Programme 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\ProgramData\Vorlagen 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\ProgramData\Startmenü 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\ProgramData\Dokumente 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien 2015-01-23 22:59 - 2015-01-23 22:59 - 00000000 _SHDL () C:\Dokumente und Einstellungen ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-25 17:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru 2015-01-25 16:56 - 2013-08-22 15:46 - 00022048 _____ () C:\Windows\setupact.log 2015-01-25 16:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-01-25 14:28 - 2014-09-25 10:46 - 00765582 _____ () C:\Windows\system32\perfh007.dat 2015-01-25 14:28 - 2014-09-25 10:46 - 00159366 _____ () C:\Windows\system32\perfc007.dat 2015-01-25 14:28 - 2014-03-18 11:03 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-24 17:23 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared 2015-01-24 17:15 - 2014-05-16 10:36 - 00000000 ____D () C:\Program Files (x86)\McAfee 2015-01-24 17:15 - 2014-03-18 10:54 - 00131226 _____ () C:\Windows\PFRO.log 2015-01-24 17:15 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-24 17:14 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\tracing 2015-01-24 17:14 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-01-24 17:12 - 2014-05-16 10:33 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-01-24 17:12 - 2013-08-22 14:25 - 00000226 _____ () C:\Windows\win.ini 2015-01-24 17:10 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\GroupPolicy 2015-01-24 13:06 - 2014-05-16 10:36 - 00000000 ____D () C:\ProgramData\McAfee 2015-01-23 23:35 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\restore 2015-01-23 23:34 - 2014-05-16 10:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer 2015-01-23 23:34 - 2014-05-16 10:24 - 00000000 ____D () C:\Program Files (x86)\Acer 2015-01-23 23:09 - 2014-05-16 11:03 - 00000000 ___HD () C:\OEM 2015-01-23 23:07 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2015-01-23 23:05 - 2014-05-16 11:09 - 00000000 ____D () C:\Windows\Panther 2015-01-23 23:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache 2015-01-23 22:59 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows NT 2015-01-23 22:59 - 2013-08-22 14:36 - 00000000 __RHD () C:\Users\Default ==================== Files in the root of some directories ======= 2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\QKTMVX 2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\SWRDAM 2014-09-01 09:18 - 2014-09-01 09:18 - 0001248 _____ () C:\Users\Arbeit Daniel\AppData\Roaming\WDXJHF 2015-01-23 23:14 - 2015-01-23 23:14 - 1878504 _____ (BroServix+2.3) C:\Users\Arbeit Daniel\AppData\Roaming\WDXJHF.exe 2014-09-25 01:18 - 2014-09-25 01:18 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some content of TEMP: ==================== C:\Users\Arbeit Daniel\AppData\Local\Temp\60B625C8-ACFD-E501-3BD2-DB933563EF4C.exe C:\Users\Arbeit Daniel\AppData\Local\Temp\7742FB50-1343-49C2-4BFE-D411A9042363.dll C:\Users\Arbeit Daniel\AppData\Local\Temp\7742FB50-1343-49C2-4BFE-D411A9042363.exe C:\Users\Arbeit Daniel\AppData\Local\Temp\AcerDocsSetup.exe C:\Users\Arbeit Daniel\AppData\Local\Temp\Launcher__10272.exe C:\Users\Arbeit Daniel\AppData\Local\Temp\oct3B7.tmp.exe C:\Users\Arbeit Daniel\AppData\Local\Temp\optprosetup.exe C:\Users\Arbeit Daniel\AppData\Local\Temp\setup_337.exe C:\Users\Arbeit Daniel\AppData\Local\Temp\SpOrder.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-05-16 10:10 ==================== End Of Log ============================ |
Themen zu neuer Laptop Win 8.1 total langsam |
appdata, arbeit, default, folge, folgende, google, html, ics, install, langsam, laptop, laufen, logdatei, logfile, malwarebytes, microsoft, neuer, rootkits, software, startup, system, total, version, win, windows, windows8.1 |