vengador | 11.10.2014 23:06 | Hallo,
ich musste den fix zwei Mal laufen lassen, weil ich beim ersten Mal vergessen hatte ****** durch meinen Windows-Accountnamen zu ersetzen.
fixlog 1: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-10-2014 01
Ran by ******** at 2014-10-11 23:52:45 Run:1
Running from C:\Users\********\Desktop
Loaded Profile: ******** (Available profiles: ******** & Saal_2)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
C:\ProgramData\Microsoft\Secure
C:\Users\******\AppData\Roaming\Irrybau
C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate
C:\Windows\System32\wadizoku.exe
C:\Windows\SysWOW64\wadizoku.exe
HKLM\...\Run: [Xukyxedoi] => "C:\Users\******\AppData\Roaming\Irrybau\ymidil.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [ATworks] => regsvr32.exe C:\Users\******\AppData\Local\ATworks\CNHL730S.DLL <===== ATTENTION
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [bootcfg] => "C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\RunOnce: [bootcfg] => "C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Policies\Explorer: [Run] "C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Command Processor: "C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe" <===== ATTENTION!
Startup: C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bootcfg.lnk
ShortcutTarget: bootcfg.lnk -> C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe (No File)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Tcpip\..\Interfaces\{10D528C3-8BA2-4936-ABEF-8FE367F33462}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{270524F5-95C9-4F05-9209-140C6F142ACF}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{59AD8773-367B-4F5B-86FF-4FAFC94F00CD}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{6E56D900-F8EA-4463-AF87-02615993FF41}: [NameServer] 8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{7234CFC1-00AD-4C0D-BB07-9172CA94234F}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{9249EE51-50DC-464A-9FF3-9D49D9AF5D76}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{9ECEF730-CB7C-4463-83D2-DD66F76B809B}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{A0D3C4AF-322E-4E44-B007-A6666274B290}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{AA3016DC-B318-4802-B590-A4E69C01F2AB}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{B2AC3C8B-758E-4DEE-9011-8F6A8274E559}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{B3597B19-F365-48EC-975E-96FD643613FB}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{C42DA61D-E9AC-4763-95D2-4DFDED8DFA6F}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{DBA24878-EBE5-4077-A9F2-906F33B2A028}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
S1 cgiysjzx; \??\C:\Windows\system32\drivers\cgiysjzx.sys [X]
S1 crbklzbk; \??\C:\Windows\system32\drivers\crbklzbk.sys [X]
S1 csdgjtlz; \??\C:\Windows\system32\drivers\csdgjtlz.sys [X]
S1 dofgpqgb; \??\C:\Windows\system32\drivers\dofgpqgb.sys [X]
S1 dycnyyuq; \??\C:\Windows\system32\drivers\dycnyyuq.sys [X]
S1 edlsjeqg; \??\C:\Windows\system32\drivers\edlsjeqg.sys [X]
S1 etgqpixz; \??\C:\Windows\system32\drivers\etgqpixz.sys [X]
S1 fkfpxnhh; \??\C:\Windows\system32\drivers\fkfpxnhh.sys [X]
S1 fqyymmff; \??\C:\Windows\system32\drivers\fqyymmff.sys [X]
S1 gsdtcoeo; \??\C:\Windows\system32\drivers\gsdtcoeo.sys [X]
S1 iuqcvcgn; \??\C:\Windows\system32\drivers\iuqcvcgn.sys [X]
S1 jwgfusfq; \??\C:\Windows\system32\drivers\jwgfusfq.sys [X]
S1 lkidqtbj; \??\C:\Windows\system32\drivers\lkidqtbj.sys [X]
S1 luxsoypz; \??\C:\Windows\system32\drivers\luxsoypz.sys [X]
S1 mgvmetif; \??\C:\Windows\system32\drivers\mgvmetif.sys [X]
S1 mnjbezcu; \??\C:\Windows\system32\drivers\mnjbezcu.sys [X]
S1 nmtieyvf; \??\C:\Windows\system32\drivers\nmtieyvf.sys [X]
S1 ogjaukqp; \??\C:\Windows\system32\drivers\ogjaukqp.sys [X]
S1 onvpkmle; \??\C:\Windows\system32\drivers\onvpkmle.sys [X]
S1 oqbclhjc; \??\C:\Windows\system32\drivers\oqbclhjc.sys [X]
S1 ozyspljp; \??\C:\Windows\system32\drivers\ozyspljp.sys [X]
S1 pymmbndk; \??\C:\Windows\system32\drivers\pymmbndk.sys [X]
S1 raqrwwst; \??\C:\Windows\system32\drivers\raqrwwst.sys [X]
S1 rdbgatpi; \??\C:\Windows\system32\drivers\rdbgatpi.sys [X]
S1 ryjgvosc; \??\C:\Windows\system32\drivers\ryjgvosc.sys [X]
S1 satfowqq; \??\C:\Windows\system32\drivers\satfowqq.sys [X]
S1 tguahlfs; \??\C:\Windows\system32\drivers\tguahlfs.sys [X]
S1 ujbtaprf; \??\C:\Windows\system32\drivers\ujbtaprf.sys [X]
S1 vndgunpt; \??\C:\Windows\system32\drivers\vndgunpt.sys [X]
S1 vprixfyj; \??\C:\Windows\system32\drivers\vprixfyj.sys [X]
S1 wikznept; \??\C:\Windows\system32\drivers\wikznept.sys [X]
S1 yipyyguc; \??\C:\Windows\system32\drivers\yipyyguc.sys [X]
S1 yjbatmlg; \??\C:\Windows\system32\drivers\yjbatmlg.sys [X]
S1 yqysouog; \??\C:\Windows\system32\drivers\yqysouog.sys [X]
S1 zbjegjjy; \??\C:\Windows\system32\drivers\zbjegjjy.sys [X]
Hosts:
Emptytemp:
*****************
"C:\ProgramData\Microsoft\Secure" directory move:
C:\ProgramData\Microsoft\Secure\Icons\IconsCacheHelper.dll => Moved successfully.
Could not move "C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll" => Scheduled to move on reboot.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp21A7.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp4894.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp6153.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp6B4.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp89E7.exe => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp89E7.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp9BE1.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmp9C80.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\tmpF1A0.tmp => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\temp\{4C49B2CD-463F-AA34-CCBD-AA5662765B1C} => Moved successfully.
C:\ProgramData\Microsoft\Secure\Icons\CachedIcons\zepplauncher.mif => Moved successfully.
Could not move "C:\ProgramData\Microsoft\Secure" directory. => Scheduled to move on reboot.
"C:\Users\******\AppData\Roaming\Irrybau" => File/Directory not found.
"C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate" => File/Directory not found.
"C:\Windows\System32\wadizoku.exe" => File/Directory not found.
"C:\Windows\SysWOW64\wadizoku.exe" => File/Directory not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Xukyxedoi => value deleted successfully.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ATworks => value deleted successfully.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\Run\\bootcfg => value deleted successfully.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\bootcfg => Value not found.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\Run => value deleted successfully.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Command Processor\\AutoRun => value deleted successfully.
C:\Users\******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bootcfg.lnk not found.
C:\Users\******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe not found.
C:\Windows\system32\GroupPolicy\Machine => Moved successfully.
C:\Windows\system32\GroupPolicy\GPT.ini => Moved successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{10D528C3-8BA2-4936-ABEF-8FE367F33462}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{270524F5-95C9-4F05-9209-140C6F142ACF}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{59AD8773-367B-4F5B-86FF-4FAFC94F00CD}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6E56D900-F8EA-4463-AF87-02615993FF41}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7234CFC1-00AD-4C0D-BB07-9172CA94234F}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9249EE51-50DC-464A-9FF3-9D49D9AF5D76}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9ECEF730-CB7C-4463-83D2-DD66F76B809B}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A0D3C4AF-322E-4E44-B007-A6666274B290}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{AA3016DC-B318-4802-B590-A4E69C01F2AB}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2AC3C8B-758E-4DEE-9011-8F6A8274E559}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B3597B19-F365-48EC-975E-96FD643613FB}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C42DA61D-E9AC-4763-95D2-4DFDED8DFA6F}\\NameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DBA24878-EBE5-4077-A9F2-906F33B2A028}\\NameServer => value deleted successfully.
cgiysjzx => Service deleted successfully.
crbklzbk => Service deleted successfully.
csdgjtlz => Service deleted successfully.
dofgpqgb => Service deleted successfully.
dycnyyuq => Service deleted successfully.
edlsjeqg => Service deleted successfully.
etgqpixz => Service deleted successfully.
fkfpxnhh => Service deleted successfully.
fqyymmff => Service deleted successfully.
gsdtcoeo => Service deleted successfully.
iuqcvcgn => Service deleted successfully.
jwgfusfq => Service deleted successfully.
lkidqtbj => Service deleted successfully.
luxsoypz => Service deleted successfully.
mgvmetif => Service deleted successfully.
mnjbezcu => Service deleted successfully.
nmtieyvf => Service deleted successfully.
ogjaukqp => Service deleted successfully.
onvpkmle => Service deleted successfully.
oqbclhjc => Service deleted successfully.
ozyspljp => Service deleted successfully.
pymmbndk => Service deleted successfully.
raqrwwst => Service deleted successfully.
rdbgatpi => Service deleted successfully.
ryjgvosc => Service deleted successfully.
satfowqq => Service deleted successfully.
tguahlfs => Service deleted successfully.
ujbtaprf => Service deleted successfully.
vndgunpt => Service deleted successfully.
vprixfyj => Service deleted successfully.
wikznept => Service deleted successfully.
yipyyguc => Service deleted successfully.
yjbatmlg => Service deleted successfully.
yqysouog => Service deleted successfully.
zbjegjjy => Service deleted successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 1.2 GB temporary data.
=> Result of Scheduled Files to move (Boot Mode: Normal) (Date&Time: 2014-10-11 23:55:12)<=
C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll => Is moved successfully.
C:\ProgramData\Microsoft\Secure => Is moved successfully.
==== End of Fixlog ==== fixlog 2: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-10-2014 01
Ran by ******* at 2014-10-11 23:58:39 Run:2
Running from C:\Users\*******\Desktop
Loaded Profile: ******* (Available profiles: ******* & Saal_2)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
C:\ProgramData\Microsoft\Secure
C:\Users\*******\AppData\Roaming\Irrybau
C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate
C:\Windows\System32\wadizoku.exe
C:\Windows\SysWOW64\wadizoku.exe
HKLM\...\Run: [Xukyxedoi] => "C:\Users\*******\AppData\Roaming\Irrybau\ymidil.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [ATworks] => regsvr32.exe C:\Users\*******\AppData\Local\ATworks\CNHL730S.DLL <===== ATTENTION
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [bootcfg] => "C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\RunOnce: [bootcfg] => "C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Policies\Explorer: [Run] "C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe"
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Command Processor: "C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe" <===== ATTENTION!
Startup: C:\Users\*******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bootcfg.lnk
ShortcutTarget: bootcfg.lnk -> C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe (No File)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
Tcpip\..\Interfaces\{10D528C3-8BA2-4936-ABEF-8FE367F33462}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{270524F5-95C9-4F05-9209-140C6F142ACF}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{59AD8773-367B-4F5B-86FF-4FAFC94F00CD}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{6E56D900-F8EA-4463-AF87-02615993FF41}: [NameServer] 8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{7234CFC1-00AD-4C0D-BB07-9172CA94234F}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{9249EE51-50DC-464A-9FF3-9D49D9AF5D76}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{9ECEF730-CB7C-4463-83D2-DD66F76B809B}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{A0D3C4AF-322E-4E44-B007-A6666274B290}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{AA3016DC-B318-4802-B590-A4E69C01F2AB}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{B2AC3C8B-758E-4DEE-9011-8F6A8274E559}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{B3597B19-F365-48EC-975E-96FD643613FB}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{C42DA61D-E9AC-4763-95D2-4DFDED8DFA6F}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
Tcpip\..\Interfaces\{DBA24878-EBE5-4077-A9F2-906F33B2A028}: [NameServer] 8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8,8.8.8.8
S1 cgiysjzx; \??\C:\Windows\system32\drivers\cgiysjzx.sys [X]
S1 crbklzbk; \??\C:\Windows\system32\drivers\crbklzbk.sys [X]
S1 csdgjtlz; \??\C:\Windows\system32\drivers\csdgjtlz.sys [X]
S1 dofgpqgb; \??\C:\Windows\system32\drivers\dofgpqgb.sys [X]
S1 dycnyyuq; \??\C:\Windows\system32\drivers\dycnyyuq.sys [X]
S1 edlsjeqg; \??\C:\Windows\system32\drivers\edlsjeqg.sys [X]
S1 etgqpixz; \??\C:\Windows\system32\drivers\etgqpixz.sys [X]
S1 fkfpxnhh; \??\C:\Windows\system32\drivers\fkfpxnhh.sys [X]
S1 fqyymmff; \??\C:\Windows\system32\drivers\fqyymmff.sys [X]
S1 gsdtcoeo; \??\C:\Windows\system32\drivers\gsdtcoeo.sys [X]
S1 iuqcvcgn; \??\C:\Windows\system32\drivers\iuqcvcgn.sys [X]
S1 jwgfusfq; \??\C:\Windows\system32\drivers\jwgfusfq.sys [X]
S1 lkidqtbj; \??\C:\Windows\system32\drivers\lkidqtbj.sys [X]
S1 luxsoypz; \??\C:\Windows\system32\drivers\luxsoypz.sys [X]
S1 mgvmetif; \??\C:\Windows\system32\drivers\mgvmetif.sys [X]
S1 mnjbezcu; \??\C:\Windows\system32\drivers\mnjbezcu.sys [X]
S1 nmtieyvf; \??\C:\Windows\system32\drivers\nmtieyvf.sys [X]
S1 ogjaukqp; \??\C:\Windows\system32\drivers\ogjaukqp.sys [X]
S1 onvpkmle; \??\C:\Windows\system32\drivers\onvpkmle.sys [X]
S1 oqbclhjc; \??\C:\Windows\system32\drivers\oqbclhjc.sys [X]
S1 ozyspljp; \??\C:\Windows\system32\drivers\ozyspljp.sys [X]
S1 pymmbndk; \??\C:\Windows\system32\drivers\pymmbndk.sys [X]
S1 raqrwwst; \??\C:\Windows\system32\drivers\raqrwwst.sys [X]
S1 rdbgatpi; \??\C:\Windows\system32\drivers\rdbgatpi.sys [X]
S1 ryjgvosc; \??\C:\Windows\system32\drivers\ryjgvosc.sys [X]
S1 satfowqq; \??\C:\Windows\system32\drivers\satfowqq.sys [X]
S1 tguahlfs; \??\C:\Windows\system32\drivers\tguahlfs.sys [X]
S1 ujbtaprf; \??\C:\Windows\system32\drivers\ujbtaprf.sys [X]
S1 vndgunpt; \??\C:\Windows\system32\drivers\vndgunpt.sys [X]
S1 vprixfyj; \??\C:\Windows\system32\drivers\vprixfyj.sys [X]
S1 wikznept; \??\C:\Windows\system32\drivers\wikznept.sys [X]
S1 yipyyguc; \??\C:\Windows\system32\drivers\yipyyguc.sys [X]
S1 yjbatmlg; \??\C:\Windows\system32\drivers\yjbatmlg.sys [X]
S1 yqysouog; \??\C:\Windows\system32\drivers\yqysouog.sys [X]
S1 zbjegjjy; \??\C:\Windows\system32\drivers\zbjegjjy.sys [X]
Hosts:
Emptytemp:
*****************
"C:\ProgramData\Microsoft\Secure" => File/Directory not found.
C:\Users\*******\AppData\Roaming\Irrybau => Moved successfully.
C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate => Moved successfully.
"C:\Windows\System32\wadizoku.exe" => File/Directory not found.
"C:\Windows\SysWOW64\wadizoku.exe" => File/Directory not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Xukyxedoi => Value not found.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\Run\\ATworks => Value not found.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\Run\\bootcfg => Value not found.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\bootcfg => Value not found.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\Run => Value not found.
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\Software\Microsoft\Command Processor\\AutoRun => Value not found.
C:\Users\*******\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\bootcfg.lnk => Moved successfully.
C:\Users\*******\AppData\Roaming\Microsoft\Windows\IEUpdate\bootcfg.exe not found.
"C:\Windows\system32\GroupPolicy\Machine" => File/Directory not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{10D528C3-8BA2-4936-ABEF-8FE367F33462}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{270524F5-95C9-4F05-9209-140C6F142ACF}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{59AD8773-367B-4F5B-86FF-4FAFC94F00CD}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6E56D900-F8EA-4463-AF87-02615993FF41}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{7234CFC1-00AD-4C0D-BB07-9172CA94234F}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9249EE51-50DC-464A-9FF3-9D49D9AF5D76}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{9ECEF730-CB7C-4463-83D2-DD66F76B809B}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{A0D3C4AF-322E-4E44-B007-A6666274B290}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{AA3016DC-B318-4802-B590-A4E69C01F2AB}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B2AC3C8B-758E-4DEE-9011-8F6A8274E559}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B3597B19-F365-48EC-975E-96FD643613FB}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C42DA61D-E9AC-4763-95D2-4DFDED8DFA6F}\\NameServer => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{DBA24878-EBE5-4077-A9F2-906F33B2A028}\\NameServer => Value not found.
cgiysjzx => Service not found.
crbklzbk => Service not found.
csdgjtlz => Service not found.
dofgpqgb => Service not found.
dycnyyuq => Service not found.
edlsjeqg => Service not found.
etgqpixz => Service not found.
fkfpxnhh => Service not found.
fqyymmff => Service not found.
gsdtcoeo => Service not found.
iuqcvcgn => Service not found.
jwgfusfq => Service not found.
lkidqtbj => Service not found.
luxsoypz => Service not found.
mgvmetif => Service not found.
mnjbezcu => Service not found.
nmtieyvf => Service not found.
ogjaukqp => Service not found.
onvpkmle => Service not found.
oqbclhjc => Service not found.
ozyspljp => Service not found.
pymmbndk => Service not found.
raqrwwst => Service not found.
rdbgatpi => Service not found.
ryjgvosc => Service not found.
satfowqq => Service not found.
tguahlfs => Service not found.
ujbtaprf => Service not found.
vndgunpt => Service not found.
vprixfyj => Service not found.
wikznept => Service not found.
yipyyguc => Service not found.
yjbatmlg => Service not found.
yqysouog => Service not found.
zbjegjjy => Service not found.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 34.4 MB temporary data.
The system needed a reboot.
==== End of Fixlog ==== frst:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-10-2014 01
Ran by ******** (administrator) on HOMER on 12-10-2014 00:02:09
Running from C:\Users\********\Desktop
Loaded Profile: ******** (Available profiles: ******** & Saal_2)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Authentec Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
() C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\capiws.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ZOOM\TpScrex.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\tv_x64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TpKnrres.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Dropbox, Inc.) C:\Users\********\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Lenovo Group Limited) C:\Program Files (x86)\ThinkPad\Utilities\SCHTASK.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Sony Corporation) C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe
(Sony Corporation) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1331288 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SAIICpl.exe [316032 2010-12-14] (Conexant systems, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-11-15] (Synaptics Incorporated)
HKLM\...\Run: [LENOVO.TPKNRRES] => C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [60920 2013-05-29] (Lenovo Group Limited)
HKLM\...\Run: [PasswordManager] => C:\Program Files\Lenovo\Password Manager\password_manager.exe [1665824 2014-06-23] (Lenovo Group Limited)
HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [PWMTRV] => rundll32 "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL",PwrMgrBkGndMonitor
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [113656 2013-01-17] (Intel Corporation)
HKLM-x32\...\Run: [KeePass 2 PreLoad] => C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe [2117632 2014-07-06] (Dominik Reichl)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe [2548248 2014-04-23] (Sony Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [HP Officejet 6700 (NET)] => C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22734160 2014-08-08] (Google)
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [GoogleChromeAutoLaunch_9B15C235115DAC872AB2008568FA0497] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [852808 2014-08-30] (Google Inc.)
HKU\S-1-5-21-210949329-1137805421-2219713098-1000\...\Run: [Evtion] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\********\AppData\Local\UVmedia\EP0NO001.DLL
Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll C:\Program Files\ThinkPad\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe ()
Startup: C:\Users\Saal_2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Google Chrome.lnk
ShortcutTarget: Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Startup: C:\Users\********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\********\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [1SecureIconsProvider] -> {FC9D8189-520A-4417-AED7-9EAC810C6FBA} => C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.50.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x86.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Services\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll No File
FF Plugin-x32: @tracker-software.com/PDF-XChange Editor Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Editor\npPDFXEditPlugin.x64.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF HKCU\...\Firefox\Extensions: [{FCF36B88-1BBA-487f-B64B-D2E8980A9293}] - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension
FF Extension: No Name - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension [2014-08-20]
Chrome:
=======
CHR Profile: C:\Users\********\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-01]
CHR Extension: (Google Drive) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-01]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (YouTube) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-01]
CHR Extension: (Google-Suche) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-01]
CHR Extension: (Media Hint) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejdagjpilmpmajpmgcojcppnhjjogfcn [2014-09-28]
CHR Extension: (Excel Online) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\iljnkagajgfdmfnnidjijobijlfjfgnb [2014-04-17]
CHR Extension: (Google Wallet) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-01]
CHR Extension: (Google Mail) - C:\Users\********\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-01]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.)
S3 DozeSvc; C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE [320560 2014-03-20] (Lenovo.)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-02-28] ()
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23784 2014-08-22] (Microsoft Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-05-29] ()
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [368624 2014-08-22] (Microsoft Corporation)
R2 OpenVPNAccessClient; C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\capiws.exe [24064 2010-08-12] () [File not signed]
R2 PMBDeviceInfoProvider; C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [481816 2014-04-23] (Sony Corporation)
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [24560 2014-06-18] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-05-29] (Intel® Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 auusb; C:\Windows\System32\DRIVERS\auusb.sys [208616 2013-07-01] (Auerswald GmbH & Co.KG )
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.)
S3 ew_hwusbdev; C:\Windows\System32\DRIVERS\ew_hwusbdev.sys [109568 2013-02-26] (Huawei Technologies Co., Ltd.) [File not signed]
S3 ew_usbenumfilter; C:\Windows\System32\DRIVERS\ew_usbenumfilter.sys [14976 2013-02-26] (Huawei Technologies Co., Ltd.) [File not signed]
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [105984 2013-01-25] (Huawei Technologies Co., Ltd.) [File not signed]
S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [76800 2013-02-26] (Huawei Technologies Co., Ltd.) [File not signed]
S3 huawei_enumerator; C:\Windows\System32\DRIVERS\ew_jubusenum.sys [91648 2013-02-26] (Huawei Technologies Co., Ltd.) [File not signed]
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [30720 2013-01-23] (Huawei Technologies Co., Ltd.) [File not signed]
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-11-16] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [269008 2014-07-17] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [125584 2014-07-17] (Microsoft Corporation)
S3 Rockusb; C:\Windows\System32\DRIVERS\rockusb.sys [65688 2014-08-17] (Fuzhou Rockchip Electronics Co,Ltd.)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [45296 2013-11-15] (Synaptics Incorporated)
R2 smihlp; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13128 2011-05-30] (Authentec Inc.)
R3 tapoas; C:\Windows\System32\DRIVERS\tapoas.sys [30720 2012-07-15] (The OpenVPN Project)
R3 usb3Hub; C:\Windows\System32\DRIVERS\usb3Hub.sys [206744 2013-06-20] (Windows (R) Win 7 DDK provider)
S1 arfbwqdh; \??\C:\Windows\system32\drivers\arfbwqdh.sys [X]
S1 camvqqvf; \??\C:\Windows\system32\drivers\camvqqvf.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-12 00:02 - 2014-10-12 00:02 - 00020612 _____ () C:\Users\********\Desktop\FRST.txt
2014-10-11 16:19 - 2014-10-11 16:16 - 00598016 _____ (Soft Inc) C:\Users\********\AppData\Roaming\7a3kUOCE.exe
2014-10-11 07:01 - 2014-10-11 07:01 - 02109952 _____ (Farbar) C:\Users\********\Desktop\FRST64.exe
2014-10-10 20:09 - 2014-10-11 16:17 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-10 20:09 - 2014-10-10 20:09 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-10 20:09 - 2014-10-10 20:09 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-10 20:09 - 2014-10-10 20:09 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-10 20:09 - 2014-10-10 20:09 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-10-10 20:09 - 2014-10-10 20:09 - 00000000 ____D () C:\Windows\system32\Macromed
2014-10-10 19:38 - 2014-10-11 16:00 - 00000808 _____ () C:\Windows\Tasks\Security Center Update - 3659286796.job
2014-10-10 19:38 - 2014-10-10 19:38 - 00003822 _____ () C:\Windows\System32\Tasks\Security Center Update - 3659286796
2014-10-09 15:45 - 2014-10-09 15:48 - 00000000 ____D () C:\AdwCleaner
2014-10-08 17:18 - 2014-10-08 17:25 - 00040374 _____ () C:\ComboFix.txt
2014-10-08 17:11 - 2014-10-08 17:18 - 00000000 ____D () C:\Qoobox
2014-10-08 16:32 - 2014-10-08 17:17 - 00000000 ____D () C:\Windows\erdnt
2014-10-08 16:32 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-08 16:32 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-08 16:32 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-08 16:32 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-08 16:32 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-08 16:32 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-08 16:32 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-08 16:32 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-08 15:33 - 2014-10-12 00:02 - 00000000 ____D () C:\FRST
2014-10-08 15:32 - 2014-10-08 15:32 - 00000474 _____ () C:\Users\********\Downloads\defogger_disable.log
2014-10-08 15:32 - 2014-10-08 15:32 - 00000000 _____ () C:\Users\********\defogger_reenable
2014-10-08 15:31 - 2014-10-08 15:31 - 00050477 _____ () C:\Users\********\Downloads\Defogger.exe
2014-10-07 18:47 - 2014-10-07 18:47 - 00000000 ____D () C:\Windows\ERUNT
2014-10-06 20:29 - 2014-10-11 13:55 - 00000000 ____D () C:\FTV
2014-10-06 20:23 - 2014-10-06 20:29 - 00000000 ____D () C:\Users\********\AppData\Local\Amazon_FireTV_Utility_App
2014-10-05 17:04 - 2014-10-06 19:50 - 00000000 ____D () C:\Users\********\AppData\Roaming\Veusdin
2014-09-30 20:25 - 2014-09-30 20:26 - 153796568 _____ (AVG Technologies) C:\Users\********\Downloads\avg_free_x86_all_2015_5315a8160.exe
2014-09-28 17:51 - 2014-09-28 17:51 - 00000213 _____ () C:\Users\********\.swfinfo
2014-09-28 13:25 - 2014-10-10 19:53 - 00000761 _____ () C:\Windows\system32\Drivers\etc\hosts.txt
2014-09-28 13:22 - 2014-10-10 19:23 - 00000000 ____D () C:\Users\********\AppData\Local\UVmedia
2014-09-28 13:22 - 2014-10-10 19:23 - 00000000 ____D () C:\Users\********\AppData\Local\ATworks
2014-09-28 13:14 - 2014-09-28 13:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPC-HC x64
2014-09-28 13:14 - 2014-09-28 13:14 - 00000000 ____D () C:\Program Files\MPC-HC
2014-09-24 21:11 - 2014-09-24 21:12 - 63850156 _____ () C:\Users\********\Downloads\xbmc-13.2-Gotham.exe
2014-09-24 21:09 - 2014-09-24 21:09 - 01609767 _____ () C:\Users\********\Downloads\plugin.video.streamzto-0.2.6.zip
2014-09-24 21:07 - 2014-09-28 20:59 - 00000000 ____D () C:\Users\********\AppData\Roaming\XBMC
2014-09-24 21:07 - 2014-09-24 21:08 - 08046503 _____ () C:\Users\********\Downloads\script.streamztv-0.0.6alpha.zip
2014-09-24 21:07 - 2014-09-24 21:07 - 00000000 ____D () C:\Users\********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\XBMC
2014-09-24 21:06 - 2014-09-24 21:12 - 00000000 ____D () C:\Program Files (x86)\XBMC
2014-09-24 21:05 - 2014-09-24 21:05 - 59604731 _____ () C:\Users\********\Downloads\xbmc-12.3.exe
2014-09-20 15:08 - 2014-09-20 15:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2014-09-20 14:12 - 2014-09-20 14:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FormPrinter
2014-09-20 14:12 - 2014-09-20 14:12 - 00000000 ____D () C:\Program Files\FormPrinter
2014-09-20 14:09 - 2014-09-20 14:09 - 02312498 _____ ( ) C:\Users\********\Downloads\FormPrinter_Free_Setup.exe
2014-09-14 15:29 - 2014-08-19 20:05 - 00374968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-09-14 15:29 - 2014-08-19 19:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-09-14 15:29 - 2014-08-19 00:29 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-09-14 15:29 - 2014-08-19 00:29 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-09-14 15:29 - 2014-08-19 00:15 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-09-14 15:29 - 2014-08-19 00:15 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-09-14 15:29 - 2014-08-19 00:14 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-09-14 15:29 - 2014-08-19 00:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-09-14 15:29 - 2014-08-19 00:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-09-14 15:29 - 2014-08-19 00:05 - 00596480 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-09-14 15:29 - 2014-08-19 00:03 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-09-14 15:29 - 2014-08-19 00:03 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-09-14 15:29 - 2014-08-18 23:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-09-14 15:29 - 2014-08-18 23:51 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-09-14 15:29 - 2014-08-18 23:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-09-14 15:29 - 2014-08-18 23:45 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-09-14 15:29 - 2014-08-18 23:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-09-14 15:29 - 2014-08-18 23:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-09-14 15:29 - 2014-08-18 23:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-09-14 15:29 - 2014-08-18 23:39 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-09-14 15:29 - 2014-08-18 23:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-09-14 15:29 - 2014-08-18 23:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-09-14 15:29 - 2014-08-18 23:38 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-09-14 15:29 - 2014-08-18 23:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-09-14 15:29 - 2014-08-18 23:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-09-14 15:29 - 2014-08-18 23:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-09-14 15:29 - 2014-08-18 23:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-09-14 15:29 - 2014-08-18 23:25 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-09-14 15:29 - 2014-08-18 23:25 - 00707072 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-09-14 15:29 - 2014-08-18 23:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-14 15:29 - 2014-08-18 23:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-09-14 15:29 - 2014-08-18 23:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-09-14 15:29 - 2014-08-18 23:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-09-14 15:29 - 2014-08-18 23:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-09-14 15:28 - 2014-08-19 01:01 - 23591424 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-09-14 15:28 - 2014-08-19 00:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-09-14 15:28 - 2014-08-19 00:20 - 02793984 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-09-14 15:28 - 2014-08-19 00:19 - 05833728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-09-14 15:28 - 2014-08-19 00:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-09-14 15:28 - 2014-08-19 00:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-09-14 15:28 - 2014-08-19 00:03 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-09-14 15:28 - 2014-08-18 23:56 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-09-14 15:28 - 2014-08-18 23:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-09-14 15:28 - 2014-08-18 23:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-09-14 15:28 - 2014-08-18 23:23 - 02104832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-09-14 15:28 - 2014-08-18 23:23 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-09-14 15:28 - 2014-08-18 23:16 - 13588480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-09-14 15:28 - 2014-08-18 23:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-09-14 15:28 - 2014-08-18 23:15 - 02310656 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-09-14 15:28 - 2014-08-18 23:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-09-14 15:28 - 2014-08-18 23:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-09-14 15:28 - 2014-08-18 22:55 - 01447424 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-09-14 15:28 - 2014-08-18 22:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-09-14 15:28 - 2014-08-18 22:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-09-14 15:28 - 2014-08-18 22:38 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-09-14 15:28 - 2014-08-18 22:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-09-14 13:24 - 2014-09-14 13:24 - 00000000 ____D () C:\Windows\Hewlett-Packard
2014-09-14 13:19 - 2014-09-14 13:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-14 12:52 - 2014-07-07 04:06 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-09-14 12:52 - 2014-07-07 04:06 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-09-14 12:52 - 2014-07-07 03:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-09-14 12:52 - 2014-07-07 03:40 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-09-14 12:52 - 2014-07-07 03:39 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-12 00:00 - 2014-03-02 20:37 - 00000000 ___RD () C:\Users\********\Dropbox
2014-10-12 00:00 - 2014-03-02 20:35 - 00000000 ____D () C:\Users\********\AppData\Roaming\Dropbox
2014-10-12 00:00 - 2014-03-02 20:21 - 00000000 ___RD () C:\Users\********\Google Drive
2014-10-12 00:00 - 2014-03-01 15:43 - 00063506 _____ () C:\Windows\PFRO.log
2014-10-12 00:00 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-12 00:00 - 2009-07-14 06:51 - 00093991 _____ () C:\Windows\setupact.log
2014-10-11 23:59 - 2014-03-01 15:21 - 01054886 _____ () C:\Windows\WindowsUpdate.log
2014-10-11 23:59 - 2009-07-14 19:58 - 00684314 _____ () C:\Windows\system32\perfh007.dat
2014-10-11 23:59 - 2009-07-14 19:58 - 00144478 _____ () C:\Windows\system32\perfc007.dat
2014-10-11 23:59 - 2009-07-14 06:45 - 00027024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-11 23:59 - 2009-07-14 06:45 - 00027024 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-11 23:54 - 2014-09-09 19:32 - 00000008 __RSH () C:\ProgramData\ntuser.pol
2014-10-11 23:52 - 2014-03-01 16:30 - 00000000 ____D () C:\ProgramData\MFAData
2014-10-11 23:52 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-10-11 13:43 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-09 16:39 - 2014-03-02 22:02 - 00000000 ____D () C:\Users\********\AppData\Roaming\KeePass
2014-10-08 20:10 - 2014-03-03 19:19 - 00000000 ____D () C:\Users\********\.freemind
2014-10-08 17:18 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-10-08 17:17 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-08 15:32 - 2014-03-01 15:21 - 00000000 ____D () C:\Users\********
2014-10-05 20:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\LiveKernelReports
2014-10-05 16:18 - 2014-03-03 21:30 - 00053028 _____ () C:\QcOSD.txt
2014-10-04 08:54 - 2014-03-07 19:47 - 00000000 ____D () C:\Users\********\Downloads\HDDScan-3.3
2014-10-03 00:53 - 2014-07-07 17:35 - 00000000 ____D () C:\Users\Saal_2
2014-10-03 00:53 - 2014-03-01 16:40 - 00000000 ____D () C:\ProgramData\lenovo
2014-10-03 00:53 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-10-02 20:10 - 2014-03-02 21:18 - 00007609 _____ () C:\Users\********\AppData\Local\resmon.resmoncfg
2014-09-28 13:23 - 2014-03-02 08:11 - 00000000 ____D () C:\Users\********\AppData\Roaming\uTorrent
2014-09-23 18:32 - 2014-03-01 16:40 - 00000000 ____D () C:\Windows\System32\Tasks\TVT
2014-09-22 08:42 - 2014-03-01 15:54 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-09-20 13:30 - 2014-03-02 20:36 - 00000000 ____D () C:\Users\********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-09-19 15:26 - 2014-05-03 10:33 - 00000000 ____D () C:\Users\********\AppData\Roaming\Audacity
2014-09-17 21:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-09-17 19:01 - 2014-03-02 16:45 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-16 16:21 - 2014-03-02 17:13 - 00001102 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-09-14 15:28 - 2014-03-01 16:26 - 00002117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2014-09-14 15:28 - 2014-03-01 16:26 - 00001912 _____ () C:\Windows\epplauncher.mif
2014-09-14 15:28 - 2014-03-01 15:48 - 01592784 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-09-14 15:27 - 2014-03-02 10:39 - 00000000 ____D () C:\Windows\system32\MRT
2014-09-14 15:27 - 2014-03-01 16:26 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2014-09-14 15:27 - 2014-03-01 16:26 - 00000000 ____D () C:\Program Files (x86)\Microsoft Security Client
2014-09-14 15:24 - 2014-03-02 10:39 - 101694776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-09-14 13:30 - 2014-03-01 16:38 - 00000000 ____D () C:\ProgramData\AVG2014
2014-09-14 13:25 - 2014-03-01 18:37 - 00000000 ____D () C:\Users\********\AppData\Roaming\HpUpdate
2014-09-14 13:25 - 2014-03-01 18:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-09-14 13:14 - 2014-03-29 16:28 - 00049802 _____ () C:\Windows\ZTEInstallInfo.log
2014-09-14 13:14 - 2014-03-29 16:28 - 00000000 ____D () C:\Windows\SysWOW64\SupportAppCB
2014-09-14 13:14 - 2014-03-01 16:48 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
Some content of TEMP:
====================
C:\Users\********\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpf4vgql.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-06 20:10
==================== End Of Log ============================ --- --- --- |