Code:
ATTFilter
Logfile of HijackThis Fork (Beta) by Alex Dragokas v.2.8.0.4
Platform: x64 Windows 10 (Home), 10.0.17134.345 (ReleaseId: 1803), Service Pack: 0
Time: 16.10.2018 - 11:04 (UTC+02:00)
Language: OS: German (0x407). Display: German (0x407). Non-Unicode: German (0x407)
Elevated: Yes
Ran by: Christian Hähnel (group: Administrator) on ZUHAUSE, FirstRun: yes
Chrome: 69.0.3497.100
Firefox: 62.0.3.6848
Edge: 11.0.17134.345
Internet Explorer: 11.0.17134.1
Default: "C:\Program Files (x86)\Mozilla Firefox\Mozilla2\firefox.exe" -osint -url "%1" (Firefox)
Boot mode: Normal
Running processes:
Number | Path
1 C:\Program Files (x86)\AntiBrowserSpy\BrowserMask.exe
1 C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 3\HDDC3Service.exe
1 C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
1 C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe
1 C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
1 C:\Program Files (x86)\G DATA\InternetSecurity\AVKBackup\AVKBackupService.exe
1 C:\Program Files (x86)\G DATA\InternetSecurity\AVKTray\AVKTray.exe
1 C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe
1 C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFirewallTray.exe
1 C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe
1 C:\Program Files (x86)\Glary Utilities 5\Integrator.exe
1 C:\Program Files (x86)\Glarysoft\Malware Hunter\Cloudscan\MHCloudSvc.exe
1 C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe
1 C:\Program Files (x86)\Glarysoft\Malware Hunter\MemfilesService.exe
1 C:\Program Files (x86)\Glarysoft\Malware Hunter\PCBooster.exe
1 C:\Program Files (x86)\Glarysoft\Malware Hunter\QuickSearch.exe
1 C:\Program Files (x86)\Glarysoft\Malware Hunter\mhtray.exe
1 C:\Program Files (x86)\Glarysoft\Malware Hunter\x64\x64ProcessAssistSvc.exe
6 C:\Program Files (x86)\Mozilla Firefox\Mozilla2\firefox.exe
1 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1 C:\Program Files\AVAST Software\Avast\AvastUI.exe
1 C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
1 C:\Program Files\CCleaner\CCleaner64.exe
1 C:\Program Files\HDCleaner\HDCleaner.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
1 C:\Program Files\Windows Defender\MSASCuiL.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1809.2-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1809.2-0\NisSrv.exe
1 C:\Users\Christian Hähnel\Downloads\HiJackThis_v2.8.0.4.exe
1 C:\Users\Christian Hähnel\Downloads\MemCompression
1 C:\Users\Christian Hähnel\Downloads\Registry
2 C:\Windows\SysWOW64\svchost.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
3 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\SystemSettingsBroker.exe
1 C:\Windows\System32\Taskmgr.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\backgroundTaskHost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dasHost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
57 C:\Windows\System32\svchost.exe
2 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\wbem\unsecapp.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\explorer.exe
O1 - Hosts: Reset contents to default
O1 - Hosts: 127.0.0.1 www.msftncsi.com
O1 - Hosts: 127.0.0.1 pre.footprintpredict.com
O1 - Hosts: 127.0.0.1 cs1.wpc.v0cdn.net
O1 - Hosts: 127.0.0.1 a-0001.a-msedge.net
O1 - Hosts: 127.0.0.1 az361816.vo.msecnd.net
O1 - Hosts: 127.0.0.1 az512334.vo.msecnd.net
O1 - Hosts: 127.0.0.1 choice.microsoft.com
O1 - Hosts: 127.0.0.1 choice.microsoft.com.nsatc.net
O1 - Hosts: 127.0.0.1 compatexchange.cloudapp.net
O1 - Hosts: 127.0.0.1 corp.sts.microsoft.com
O1 - Hosts: 127.0.0.1 corpext.msitadfs.glbdns2.microsoft.com
O1 - Hosts: 127.0.0.1 df.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 diagnostics.support.microsoft.com
O1 - Hosts: 127.0.0.1 fe2.update.microsoft.com.akadns.net
O1 - Hosts: 127.0.0.1 feedback.microsoft-hohm.com
O1 - Hosts: 127.0.0.1 feedback.search.microsoft.com
O1 - Hosts: 127.0.0.1 feedback.windows.com
O1 - Hosts: 127.0.0.1 i1.services.social.microsoft.com
O1 - Hosts: 127.0.0.1 i1.services.social.microsoft.com.nsatc.net
O1 - Hosts: 127.0.0.1 oca.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 oca.telemetry.microsoft.com.nsatc.net
O1 - Hosts: 127.0.0.1 preview.msn.com
O1 - Hosts: 127.0.0.1 rad.msn.com
O1 - Hosts: 127.0.0.1 redir.metaservices.microsoft.com
O1 - Hosts: 127.0.0.1 reports.wes.df.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 services.wes.df.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 settings-sandbox.data.microsoft.com
O1 - Hosts: 127.0.0.1 sls.update.microsoft.com.akadns.net
O1 - Hosts: 127.0.0.1 sqm.df.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 sqm.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 sqm.telemetry.microsoft.com.nsatc.net
O1 - Hosts: 127.0.0.1 statsfe1.ws.microsoft.com
O1 - Hosts: 127.0.0.1 statsfe2.update.microsoft.com.akadns.net
O1 - Hosts: 127.0.0.1 statsfe2.ws.microsoft.com
O1 - Hosts: 127.0.0.1 survey.watson.microsoft.com
O1 - Hosts: 127.0.0.1 telecommand.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 telecommand.telemetry.microsoft.com.nsatc.net
O1 - Hosts: 127.0.0.1 telemetry.appex.bing.net
O1 - Hosts: 127.0.0.1 telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 telemetry.urs.microsoft.com
O1 - Hosts: 127.0.0.1 vortex-sandbox.data.microsoft.com
O1 - Hosts: 127.0.0.1 vortex-win.data.microsoft.com
O1 - Hosts: 127.0.0.1 vortex.data.microsoft.com
O1 - Hosts: 127.0.0.1 watson.live.com
O1 - Hosts: 127.0.0.1 watson.microsoft.com
O1 - Hosts: 127.0.0.1 watson.ppe.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 watson.telemetry.microsoft.com
O1 - Hosts: 127.0.0.1 watson.telemetry.microsoft.com.nsatc.net
O1 - Hosts: 127.0.0.1 wes.df.telemetry.microsoft.com
O4 - HKCU\..\Run: [AntiBrowserSpy - BrowserMask] = C:\Program Files (x86)\AntiBrowserSpy\BrowserMask.exe
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR
O4 - HKCU\..\StartupApproved\Run: [GUDelayStartup] (2018/04/14) = C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe -delayrun
O4 - HKLM\..\Run: [AvastUI.exe] = C:\Program Files\AVAST Software\Avast\AvLaunch.exe /gui
O4 - HKLM\..\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
O4 - HKLM\..\Session Manager: [BootExecute] = C:\WINDOWS\system32\autochk.exe *
O4 - HKLM\..\StartupApproved\Run: [SecurityHealth] (1601/01/01) = C:\Program Files\Windows Defender\MSASCuiL.exe
O4 - HKU\S-1-5-19\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4 - HKU\S-1-5-20\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade
O4 - User Startup: C:\Users\Christian Hähnel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk -> C:\Program Files (x86)\ERUNT\AUTOBACK.EXE %SystemRoot%\ERDNT\AutoBackup\#Date# /noconfirmdelete /noprogresswindow
O4-32 - HKLM\..\Run: [MalTray] = C:\Program Files (x86)\Glarysoft\Malware Hunter\mhtray.exe /autorun
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE (file missing)
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll (file missing)
O17 - DHCP DNS 1: 192.168.178.1
O21 - HKLM\..\ShellIconOverlayIdentifiers: OneDrive7 - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers: avast - {472083B0-C522-11CF-8763-00608CC02F24} - C:\Program Files\AVAST Software\Avast\ashShA64.dll
O21-32 - HKLM\..\ShellIconOverlayIdentifiers: OneDrive7 - {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} - (no file)
O22 - Task (Job): StartupStar Firewall.job - C:\Program Files (x86)\StartupStar\StartupStar.exe -m
O22 - Task: (disabled) Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O22 - Task: (disabled) Adobe Flash Player NPAPI Notifier - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_122_Plugin.exe -check plugin
O22 - Task: (disabled) Driver Booster SkipUAC (Christian Hähnel) - C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe /skipuac (file missing)
O22 - Task: (disabled) GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: (disabled) GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: (disabled) PrivaZer_SkipUAC - C:\Program Files (x86)\PrivaZer\PrivaZer.exe $(Arg0)
O22 - Task: (disabled) StartupStar Firewall - C:\Program Files (x86)\StartupStar\StartupStar.exe -m
O22 - Task: (disabled) \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -SettingChange - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\HelloFace\FODCleanupTask - C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndContinueUpdates - {0DC331EE-8438-49D5-A721-E10B937CE459} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndScanForUpdates - {D5A04D91-6FE6-4FE4-A98A-FEB4500C5AF7} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Speech\HeadsetButtonPress - C:\WINDOWS\system32\speech_onecore\common\SpeechRuntime.exe StartedFromTask (Microsoft)
O22 - Task: (disabled) \S-1-5-21-1680807977-1549783084-2757732481-1001\DataSenseLiveTileTask - C:\WINDOWS\System32\DataUsageLiveTileTask.exe
O22 - Task: (disabled) klcp_update - C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe /verysilent /update /freq=30
O22 - Task: Adobe Flash Player Updater - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O22 - Task: Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
O22 - Task: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe
O22 - Task: CCleanerSkipUAC - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
O22 - Task: Erunt - C:\Program Files (x86)\ERUNT\ERUNT.EXE
O22 - Task: GMHSkipUAC - C:\Program Files (x86)\Glarysoft\Malware Hunter\MalwareHunter.exe $(Arg0)
O22 - Task: HDCleaner Monitoring - C:\PROGRAM FILES\HDCLEANER\HDCleaner.exe /MONITOR/
O22 - Task: HDCleanerSkipUAC - C:\Program Files\HDCleaner\HDCleaner.exe /SKIPUAC/
O22 - Task: \Avast Software\Overseer - C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe /from_scheduler:1
O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -SettingChange - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft)
O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -ProtectionStateChanged -FreeNetworkOnly - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft)
O22 - Task: \Microsoft\Windows\DirectX\DXGIAdapterCache - C:\WINDOWS\system32\dxgiadaptercache.exe (Microsoft)
O22 - Task: \Microsoft\Windows\InstallService\ScanForUpdates - {A558C6A5-B42B-4C98-B610-BF9559143139} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: \Microsoft\Windows\InstallService\ScanForUpdatesAsUser - {DDAFAEA2-8842-4E96-BADE-D44A8D676FDB} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: \Microsoft\Windows\InstallService\SmartRetry - {F3A219C3-2698-4CBF-9C07-037EDB8E72E6} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft)
O22 - Task: \Microsoft\Windows\LanguageComponentsInstaller\ReconcileLanguageResources - {D0582E3B-3126-4CAA-9155-AC37C912A489} - C:\WINDOWS\System32\LanguageOverlayServer.dll (Microsoft)
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client"
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server"
O22 - Task: \Microsoft\Windows\WaaSMedic\PerformRemediation - {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32},None - C:\WINDOWS\System32\WaaSMedicSvc.dll (Microsoft)
O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Cleanup - C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe -IdleTask -TaskName WdCleanup
O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55
O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Verification - C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MpCmdRun.exe -IdleTask -TaskName WdVerification
O23 - Service R2: Ashampoo HDD Control 3 Service - (HDDC3Service) - C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 3\HDDC3Service.exe
O23 - Service R2: Avast Antivirus - (avast! Antivirus) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service R2: G DATA ANTIVIRUS Proxy - (AVKProxy) - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
O23 - Service R2: G DATA Backup Service - (GDBackupSvc) - C:\Program Files (x86)\G DATA\InternetSecurity\AVKBackup\AVKBackupService.exe
O23 - Service R2: G DATA Dateisystem Wächter - (AVKWCtl) - C:\Program Files (x86)\G DATA\InternetSecurity\AVK\AVKWCtlx64.exe
O23 - Service R2: HP CUE DeviceDiscovery Service - (hpqddsvc) - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt; "ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
O23 - Service R2: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service R2: Windows Defender Antivirus Service - (WinDefend) - C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\MsMpEng.exe
O23 - Service R2: Windows Defender Antivirus-Netzwerkinspektionsdienst - (WdNisSvc) - C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1809.2-0\NisSrv.exe
O23 - Service R2: hpqcxs08 - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt; "ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
O23 - Service R3: G*DATA Personal Firewall - (GDFwSvc) - C:\Program Files (x86)\G DATA\InternetSecurity\Firewall\GDFwSvcx64.exe
O23 - Service R3: G*DATA Scanner - (GDScan) - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
O23 - Service R3: aswbIDSAgent - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service S2: Net Driver HPZ12 - C:\WINDOWS\System32\svchost.exe -k HPZ12; "ServiceDll" = C:\Windows\System32\HPZinw12.dll
O23 - Service S2: Pml Driver HPZ12 - C:\WINDOWS\System32\svchost.exe -k HPZ12; "ServiceDll" = C:\Windows\System32\HPZipm12.dll
O23 - Service S2: Wondershare Application Framework Service - (WsAppService) - C:\Program Files (x86)\Wondershare\WAF\2.4.3.237\WsAppService.exe
O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service S3: AvastWscReporter - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe /runassvc
O23 - Service S3: Defragmentation-Service - (DfSdkS) - C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 3\DfsdkS64.exe
O23 - Service S3: Firebird Server - MAGIX Instance - (FirebirdServerMAGIXInstance) - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
--
End of file - Time spent: 38 sec. - 34320 bytes, CRC32: FFFFFFFF. Sign: 똸ꏕ