|
Plagegeister aller Art und deren Bekämpfung: Ich habe Probleme mit right coupon und anderem!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.04.2015, 12:41 | #1 | |
| Ich habe Probleme mit right coupon und anderem! Hallo, und zwar habe ich wie im Header angegeben, dass ich mit right coupon Probleme habe! Ich hab versucht es unter Programme deinstallieren ging leider nicht! Auch im internet hab ich dazu nichts wirkungsvolles gefunden! Desweiteren hab ich Probleme mit "hyperlinks" ->browser hijacker? Sind meist grün oder blau doppelt unterstrichene wörter die verlinkt sind! Ist auch ziehmlich nervig... Hierbei hatte ich auch schon etliche male versucht das zu beheben aber ohne erfolg! Bitte um Hilfe, bin im Moment so verzweifelt, dass ich am liebsten den PC neu aufsetzen würde! (das ich aber zu vermeiden versuche) Hier der Auszug aus der FRST.txt! FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015 Ran by Christian (administrator) on CHRIS on 12-04-2015 13:48:05 Running from C:\Users\Christian\Downloads Loaded Profiles: Christian & (Available profiles: Christian) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe () C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Nitro PDF Software) C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe () C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe (Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Windows\System32\PnkBstrA.exe () C:\Program Files\CyberLink\Shared files\RichVideo64.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD12\PDVD12Serv.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Bohemia Interactive) C:\Program Files (x86)\Steam\steamapps\common\Arma 3\arma3launcher.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe () C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudService.exe () C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudInstallWizard.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_16_0_0_305.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-11-21] (Intel Corporation) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2673296 2015-03-28] (NVIDIA Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13662936 2013-10-24] (Realtek Semiconductor) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-02-13] (Apple Inc.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [tvncontrol] => C:\Program Files\TightVNC\tvnserver.exe [2179056 2013-07-19] (GlavSoft LLC.) HKLM\...\Run: [PocketCloud Location] => C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\WyseBrowser.exe [883104 2012-05-11] (Wyse Technology Inc.) HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111576 2013-08-05] (CyberLink) HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [490760 2014-03-12] (CyberLink Corp.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-02-13] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-07] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG) HKLM\...\Policies\Explorer: [ConfirmFileDelete] 1 HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [AppLauncher] => C:\Program Files (x86)\Ashampoo\Ashampoo AppLauncher\AppLauncher.exe HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [AppLauncher] => C:\Program Files (x86)\Ashampoo\Ashampoo AppLauncher\AppLauncher.exe HKU\S-1-5-21-3726084679-4115828952-4147541340-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-09] (Valve Corporation) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [9797416 2015-02-25] (Visicom Media Inc.) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001\...\Policies\system: [NoDispCPL] 0 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-09] (Valve Corporation) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [31087200 2015-01-23] (Skype Technologies S.A.) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [9797416 2015-02-25] (Visicom Media Inc.) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\system: [NoDispCPL] 0 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-09] (Valve Corporation) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\ManyCam.exe [9797416 2015-02-25] (Visicom Media Inc.) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Policies\system: [NoDispCPL] 0 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Policies\Explorer: [NoInstrumentation] 1 HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\...\Policies\Explorer: [NoSetTaskbar] 0 HKU\S-1-5-18\...\Run: [AppLauncher] => C:\Program Files (x86)\Ashampoo\Ashampoo AppLauncher\AppLauncher.exe CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3726084679-4115828952-4147541340-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3726084679-4115828952-4147541340-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation) Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\c7l5xvuu.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-14] () FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2015-01-13] (EA Digital Illusions CE AB) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-14] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2015-01-13] (EA Digital Illusions CE AB) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-04] (Intel Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2014-05-15] (Nitro PDF) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-03-13] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-03-13] (NVIDIA Corporation) FF Extension: Avira Browser Safety - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\c7l5xvuu.default\Extensions\abs@avira.com [2015-04-01] FF Extension: Mozilla Firefox Hotfixer - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\c7l5xvuu.default\Extensions\veggy@veggyAddon.com [2015-03-25] FF Extension: Zoom It - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\c7l5xvuu.default\Extensions\{f442ece9-44e7-fe7e-383d-3ae2886516d9} [2015-04-11] FF Extension: {636b874f-1c90-4a1a-b273-f9bd8d20edac} - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\c7l5xvuu.default\Extensions\{636b874f-1c90-4a1a-b273-f9bd8d20edac}.xpi [2015-02-14] FF Extension: Video DownloadHelper - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\c7l5xvuu.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2015-03-30] FF Extension: Adblock Plus - C:\Users\Christian\AppData\Roaming\Mozilla\Firefox\Profiles\c7l5xvuu.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-03-27] FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-03-26] Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 AHDDC2; C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe [1518504 2012-07-30] () S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-07] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-04-07] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-07] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-07] (Avira Operations GmbH & Co. KG) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.) R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [178424 2014-12-31] (Avira Operations GmbH & Co. KG) S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation) R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation) R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152144 2015-03-28] (NVIDIA Corporation) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-11-21] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation) R2 NitroDriverReadSpool9; C:\Program Files\Nitro\Pro 9\NitroPDFDriverService9x64.exe [230920 2014-05-15] (Nitro PDF Software) R2 NitroUpdateService; C:\Program Files\Nitro\Pro 9\Nitro_UpdateService.exe [417800 2014-05-15] () R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1878672 2015-03-28] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [22995600 2015-03-28] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1930608 2015-03-28] (Electronic Arts) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-02-11] () R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-02-11] () R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-08-08] () S2 tvnserver; C:\Program Files\TightVNC\tvnserver.exe [2179056 2013-07-19] (GlavSoft LLC.) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation) R2 WysePocketCloud; C:\Program Files (x86)\Wyse\PocketCloud Windows Companion\PocketCloudService.exe [177056 2012-05-11] () [File not signed] S2 4ef60154; "C:\Windows\system32\rundll32.exe" "c:\Program Files (x86)\Optimizer Pro 3.38\OptProMon.dll",ENT ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-02-04] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-02-04] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2015-02-04] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-02-04] (Avira Operations GmbH & Co. KG) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) R3 ManyCam; C:\Windows\system32\DRIVERS\mcvidrv.sys [49272 2014-12-29] (Visicom Media Inc.) R3 mcaudrv_simple; C:\Windows\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (Visicom Media Inc.) R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation) S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-03-28] (NVIDIA Corporation) R3 NVVADARM; C:\Windows\system32\drivers\nvvadarm.sys [40136 2015-03-13] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation) S3 RtlWlanu; C:\Windows\system32\DRIVERS\rtwlanu.sys [2968280 2014-01-15] (Realtek Semiconductor Corporation ) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation) R3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-12 13:14 - 2015-04-12 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wyse 2015-04-12 13:14 - 2015-04-12 13:14 - 00000000 ____D () C:\Program Files (x86)\Wyse 2015-04-12 12:42 - 2015-04-12 12:42 - 21178512 _____ (Wyse Technology) C:\Users\Christian\Downloads\PocketCloud Windows Companion_v2.4.19.exe 2015-04-12 12:42 - 2015-04-12 12:42 - 00000000 ____D () C:\Users\Christian\AppData\Local\Downloaded Installations 2015-04-12 12:30 - 2015-04-12 12:30 - 00000000 ____D () C:\Users\Christian\AppData\Local\PocketCloudDesktopApp 2015-04-12 12:26 - 2015-04-12 12:26 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\icons 2015-04-11 23:33 - 2015-04-11 23:33 - 00083150 _____ () C:\Users\Christian\Downloads\b19MGEx2.htm 2015-04-08 10:42 - 2015-04-08 10:42 - 00000000 ____D () C:\ProgramData\TightVNC 2015-04-08 10:42 - 2015-04-08 10:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TightVNC 2015-04-08 10:42 - 2015-04-08 10:42 - 00000000 ____D () C:\Program Files\TightVNC 2015-04-08 10:41 - 2015-04-08 10:41 - 02367488 _____ () C:\Users\Christian\Downloads\tightvnc-2.7.10-setup-64bit.msi 2015-04-08 10:39 - 2015-04-08 10:46 - 00000000 ____D () C:\Program Files\RealVNC 2015-04-08 10:39 - 2015-04-08 10:45 - 00000000 ____D () C:\Users\Christian\AppData\Local\RealVNC 2015-04-08 10:39 - 2015-04-08 10:39 - 12702888 _____ (RealVNC Ltd ) C:\Users\Christian\Downloads\VNC-5.2.3-Windows.exe 2015-04-08 10:39 - 2015-04-08 10:39 - 00000000 ____D () C:\ProgramData\RealVNC-Service 2015-04-06 17:40 - 2015-04-06 17:48 - 1652134629 _____ (Igor Pavlov) C:\Users\Christian\Downloads\RLP.exe 2015-04-06 17:33 - 2015-04-06 17:33 - 00000000 _____ () C:\autoexec.bat 2015-04-06 17:32 - 2015-04-06 17:49 - 00000000 ____D () C:\Windows\ACF5FE1B377240688B872D2A6EFD0A05.TMP 2015-04-06 17:32 - 2015-04-06 17:32 - 00000000 ____D () C:\Program Files\Enigma Software Group 2015-04-06 17:30 - 2015-04-06 17:31 - 00728960 _____ (Enigma Software Group USA, LLC.) C:\Users\Christian\Downloads\SpyHunter-installer.exe 2015-04-06 13:11 - 2015-04-06 13:11 - 00000000 ____D () C:\Users\Christian\Desktop\Bandicam 2015-04-05 21:45 - 2015-04-05 21:46 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-05 21:45 - 2015-04-05 21:45 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-01 22:29 - 2015-04-01 22:29 - 00001265 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2015-04-01 22:29 - 2015-04-01 22:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-04-01 22:28 - 2015-04-01 22:29 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft 2015-04-01 22:28 - 2015-04-01 22:28 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack 2015-04-01 22:27 - 2015-04-01 22:29 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\DVDVideoSoft 2015-04-01 22:27 - 2015-04-01 22:27 - 64578440 _____ (DVDVideoSoft Ltd. ) C:\Users\Christian\Downloads\FreeStudio.exe 2015-03-30 23:00 - 2015-03-30 23:00 - 00000000 ____D () C:\ProgramData\Samsung 2015-03-30 22:59 - 2015-03-30 22:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2015-03-30 22:59 - 2015-03-30 22:59 - 00000000 ____D () C:\Program Files (x86)\MyFree Codec 2015-03-30 22:58 - 2015-03-30 22:59 - 00000000 ____D () C:\Users\Christian\Documents\SelfMV 2015-03-30 22:58 - 2015-03-30 22:58 - 00000000 ____D () C:\Users\Public\Documents\NativeFus_Log 2015-03-30 22:57 - 2015-03-30 23:00 - 00000000 ____D () C:\Users\Christian\Documents\samsung 2015-03-30 22:57 - 2015-03-30 22:58 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Samsung 2015-03-30 22:57 - 2015-03-30 22:57 - 42543488 _____ (Samsung Electronics Co., Ltd.) C:\Users\Christian\Downloads\Kies3Setup.exe 2015-03-30 22:57 - 2015-03-30 22:57 - 00001993 _____ () C:\Users\Public\Desktop\Samsung Kies 3.lnk 2015-03-30 22:57 - 2015-03-30 22:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2015-03-30 22:57 - 2015-03-30 22:57 - 00000000 ____D () C:\Program Files (x86)\Samsung 2015-03-30 22:57 - 2014-05-07 17:42 - 00144664 _____ (MAPILab Ltd. & Add-in Express Ltd.) C:\Windows\SysWOW64\secman.dll 2015-03-30 22:34 - 2015-03-30 22:34 - 00000000 ____D () C:\Users\Christian\dwhelper 2015-03-30 21:14 - 2015-03-30 21:14 - 00000000 ____D () C:\Program Files (x86)\Microsoft ASP.NET 2015-03-28 13:30 - 2015-03-28 13:30 - 00002081 _____ () C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk 2015-03-28 13:26 - 2015-03-13 17:38 - 00622224 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2015-03-28 13:24 - 2015-03-13 21:41 - 32114888 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 25460880 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 20466376 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 17258024 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 13297144 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 13210080 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 10775080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 10715864 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 10262160 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2015-03-28 13:24 - 2015-03-13 21:41 - 03611792 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 03249352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 02906928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 01896136 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6434788.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcvadgenco64.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6434788.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00997856 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00970384 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00944784 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00930448 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00909512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00878328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00833680 _____ () C:\Windows\system32\nvmcumd.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00496272 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00400584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00390288 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00354112 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00346824 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00306208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00195728 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2015-03-28 13:24 - 2015-03-13 21:41 - 00178512 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00164568 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00101576 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcaparm.dll 2015-03-28 13:24 - 2015-03-13 21:41 - 00040136 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvadarm.sys 2015-03-28 13:24 - 2015-03-13 21:41 - 00030536 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2015-03-28 13:21 - 2015-04-03 12:23 - 00001401 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk 2015-03-28 13:21 - 2015-03-28 13:21 - 34603752 _____ (NVIDIA Corporation) C:\Users\Christian\Downloads\GeForce_Experience_v2.2.2.0.exe 2015-03-28 13:21 - 2015-03-28 13:21 - 00000000 ____D () C:\Users\Christian\AppData\Local\NVIDIA Corporation 2015-03-28 13:21 - 2015-03-28 13:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2015-03-28 13:21 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2015-03-28 13:21 - 2015-03-28 05:44 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2015-03-28 13:21 - 2015-03-28 05:43 - 01756424 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2015-03-28 13:21 - 2015-03-28 05:43 - 01570672 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2015-03-28 13:21 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2015-03-28 13:21 - 2014-11-22 12:46 - 00035472 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2015-03-28 13:21 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2015-03-28 13:15 - 2015-04-11 15:42 - 00000000 ____D () C:\Users\Christian\AppData\Local\Arma 3 Launcher 2015-03-28 13:15 - 2015-03-28 13:15 - 00000000 ____D () C:\Users\Christian\AppData\Local\Bohemia_Interactive 2015-03-27 16:41 - 2015-03-27 16:48 - 00001661 _____ () C:\Users\Christian\Desktop\Neues Textdokument.txt 2015-03-26 18:40 - 2015-03-26 18:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-03-25 18:20 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-03-25 18:20 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-03-25 18:20 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-03-25 18:20 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-03-25 18:20 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-03-25 18:20 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-03-25 18:20 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-03-22 19:34 - 2015-03-22 19:34 - 00024277 _____ () C:\Users\Christian\Downloads\Addition.txt 2015-03-22 19:32 - 2015-04-12 13:48 - 00022020 _____ () C:\Users\Christian\Downloads\FRST.txt 2015-03-22 19:32 - 2015-04-12 13:48 - 00000000 ____D () C:\FRST 2015-03-22 19:32 - 2015-03-22 19:32 - 02095616 _____ (Farbar) C:\Users\Christian\Downloads\FRST64.exe 2015-03-15 21:15 - 2015-03-15 21:18 - 00000000 ____D () C:\AdwCleaner 2015-03-15 21:15 - 2015-03-15 21:15 - 02171392 _____ () C:\Users\Christian\Downloads\adwcleaner_4.112.exe ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-12 13:47 - 2015-03-07 14:41 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Nitro PDF 2015-04-12 13:18 - 2015-02-11 12:25 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3726084679-4115828952-4147541340-1001 2015-04-12 13:11 - 2015-02-14 03:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-12 13:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru 2015-04-12 12:49 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp 2015-04-12 12:36 - 2014-10-21 10:07 - 01453160 _____ () C:\Windows\WindowsUpdate.log 2015-04-12 12:26 - 2015-02-11 16:24 - 00000000 ____D () C:\ProgramData\Package Cache 2015-04-12 11:52 - 2015-02-11 19:06 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-04-12 11:17 - 2015-02-11 12:43 - 00003934 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{2F682299-1898-488B-AFA2-81C0F099C3E7} 2015-04-12 11:15 - 2015-02-12 17:43 - 00000000 ____D () C:\Users\Christian\AppData\Local\Arma 3 2015-04-12 11:14 - 2014-09-30 00:52 - 00000450 _____ () C:\Windows\Tasks\simplitec Service Provider.job 2015-04-09 20:44 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness 2015-04-08 10:47 - 2015-02-24 12:53 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Skype 2015-04-07 21:26 - 2015-02-11 12:19 - 00000000 ____D () C:\Users\Christian 2015-04-07 19:59 - 2015-02-14 03:06 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\Avira 2015-04-07 19:59 - 2015-02-14 03:05 - 00002026 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2015-04-07 19:59 - 2015-02-14 03:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2015-04-07 19:59 - 2015-02-14 03:04 - 00000000 ____D () C:\ProgramData\Avira 2015-04-07 19:59 - 2014-04-28 13:38 - 00765378 _____ () C:\Windows\system32\perfh007.dat 2015-04-07 19:59 - 2014-04-28 13:38 - 00159696 _____ () C:\Windows\system32\perfc007.dat 2015-04-07 19:59 - 2014-03-18 17:26 - 01780340 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-07 19:53 - 2014-09-29 22:16 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-04-07 19:53 - 2013-08-22 16:46 - 00115425 _____ () C:\Windows\setupact.log 2015-04-07 19:53 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-07 19:52 - 2014-03-18 10:16 - 00520102 _____ () C:\Windows\PFRO.log 2015-04-07 19:52 - 2013-08-22 17:43 - 00000000 ____D () C:\Windows\DigitalLocker 2015-04-06 21:39 - 2015-02-18 16:01 - 00000000 ____D () C:\Users\Christian\AppData\Roaming\TS3Client 2015-03-30 22:57 - 2014-04-25 09:22 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-03-28 13:26 - 2014-09-29 22:15 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation 2015-03-28 13:26 - 2014-09-29 22:15 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2015-03-28 13:25 - 2014-09-29 22:15 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2015-03-28 13:21 - 2015-02-11 12:20 - 00000000 ____D () C:\Users\Christian\AppData\Local\NVIDIA 2015-03-28 13:18 - 2015-02-11 13:52 - 00000000 ____D () C:\ProgramData\Origin 2015-03-28 13:17 - 2015-02-11 13:52 - 00000000 ____D () C:\Program Files (x86)\Origin 2015-03-28 13:10 - 2015-02-15 15:15 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-28 13:10 - 2014-04-29 12:58 - 00000000 ____D () C:\Windows\sv 2015-03-28 13:08 - 2015-02-11 20:53 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-03-28 13:08 - 2015-02-11 20:53 - 00000000 ____D () C:\Windows\system32\appraiser 2015-03-25 18:23 - 2013-08-22 15:25 - 00262144 ___SH () C:\Windows\system32\config\BBI 2015-03-21 14:25 - 2015-02-14 05:02 - 00001408 _____ () C:\Users\Christian\AppData\Roaming\BreakingPoint_Options.ini 2015-03-21 13:59 - 2015-02-14 05:01 - 00000302 _____ () C:\Users\Christian\AppData\Roaming\BreakingPoint_Login.ini 2015-03-17 19:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache 2015-03-13 21:41 - 2014-09-29 22:15 - 24775368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 18580512 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 16022016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 14121624 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 03303448 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 01540240 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 00073872 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 00060560 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2015-03-13 21:41 - 2014-09-29 22:15 - 00027441 _____ () C:\Windows\system32\nvinfo.pb 2015-03-13 18:16 - 2014-09-29 22:16 - 06861968 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-03-13 18:16 - 2014-09-29 22:16 - 03526856 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-03-13 18:16 - 2014-09-29 22:16 - 02559808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-03-13 18:16 - 2014-09-29 22:16 - 00935056 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-03-13 18:16 - 2014-09-29 22:16 - 00386248 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-03-13 18:16 - 2014-09-29 22:16 - 00062608 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll ==================== Files in the root of some directories ======= 2015-02-14 05:01 - 2015-03-21 13:59 - 0000302 _____ () C:\Users\Christian\AppData\Roaming\BreakingPoint_Login.ini 2015-02-14 05:02 - 2015-03-21 14:25 - 0001408 _____ () C:\Users\Christian\AppData\Roaming\BreakingPoint_Options.ini 2015-02-12 16:49 - 2015-02-12 16:49 - 0000046 _____ () C:\Users\Christian\AppData\Roaming\WB.CFG 2014-09-29 22:17 - 2014-09-29 22:17 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2014-09-30 00:43 - 2014-09-30 00:44 - 0000119 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log 2014-09-30 00:28 - 2014-09-30 00:29 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log 2014-09-30 00:43 - 2014-09-30 00:43 - 0000032 _____ () C:\ProgramData\{5A454EC5-217A-42a5-8CE1-2DDEC4E70E01}.log 2014-09-30 00:42 - 2014-09-30 00:42 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log 2014-09-30 00:26 - 2014-09-30 00:27 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log 2014-09-30 00:42 - 2014-09-30 00:42 - 0000032 _____ () C:\ProgramData\{E1646825-D391-42A0-93AA-27FA810DA093}.log 2014-09-30 00:27 - 2014-09-30 00:28 - 0000110 _____ () C:\ProgramData\{E3739848-5329-48E3-8D28-5BBD6E8BE384}.log 2014-09-30 00:29 - 2014-09-30 00:29 - 0000110 _____ () C:\ProgramData\{E3D04529-6EDB-11D8-A372-0050BAE317E1}.log Some content of TEMP: ==================== C:\Users\Christian\AppData\Local\Temp\7748F927-9B3B-1CB6-CF6B-C62F6F1F287F.dll C:\Users\Christian\AppData\Local\Temp\7748F927-9B3B-1CB6-CF6B-C62F6F1F287F.exe C:\Users\Christian\AppData\Local\Temp\AppLauncher.exe C:\Users\Christian\AppData\Local\Temp\avgnt.exe C:\Users\Christian\AppData\Local\Temp\bdfilters.dll C:\Users\Christian\AppData\Local\Temp\D60CD6E2-FE24-B932-D475-E69D71B0BD3F.exe C:\Users\Christian\AppData\Local\Temp\Quarantine.exe C:\Users\Christian\AppData\Local\Temp\SHSetup.exe C:\Users\Christian\AppData\Local\Temp\SkypeSetup.exe C:\Users\Christian\AppData\Local\Temp\sonarinst.exe C:\Users\Christian\AppData\Local\Temp\SpOrder.dll C:\Users\Christian\AppData\Local\Temp\sqlite3.dll C:\Users\Christian\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-10 18:40 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- Addition.txt Zitat:
Geändert von ChrisGi (12.04.2015 um 13:28 Uhr) |
12.04.2015, 13:06 | #2 |
/// the machine /// TB-Ausbilder | Ich habe Probleme mit right coupon und anderem! hi,
__________________Addition.txt fehlt noch
__________________ |
12.04.2015, 13:11 | #3 |
| Ich habe Probleme mit right coupon und anderem! oops!
__________________Is ergänzt |
12.04.2015, 18:44 | #4 |
/// the machine /// TB-Ausbilder | Ich habe Probleme mit right coupon und anderem! Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Ich habe Probleme mit right coupon und anderem! |
anderem, askbar, aufsetzen, beheben, blau, browser, browser hijacker, deinstalliere, deinstallieren, doppel, doppelt, etliche, hijacker, hyperlinks, interne, internet, neu, nichts, probleme, programme, verlinkt, vermeide, versuche, versucht, verzweifelt, würde |