Schildkröte2 | 10.12.2014 23:19 | Für den lieben Schrauber :):) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 10.12.2014
Suchlauf-Zeit: 22:38:17
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.12.10.09
Rootkit Datenbank: v2014.12.08.03
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Lenovo
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 386075
Verstrichene Zeit: 7 Min, 19 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 22
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Löschen bei Neustart, [022f9fc26c10320461d0e0ecb84a16ea],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [022f9fc26c10320461d0e0ecb84a16ea],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Löschen bei Neustart, [949d3a27562612247eb43d8fd23007f9],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [949d3a27562612247eb43d8fd23007f9],
Trojan.BHO, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [d859dc850c70e6503421fae8f30ffe02],
Trojan.BHO, HKU\S-1-5-21-3019136568-2950334141-3358811229-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [d859dc850c70e6503421fae8f30ffe02],
Trojan.BHO, HKU\S-1-5-21-3019136568-2950334141-3358811229-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [d859dc850c70e6503421fae8f30ffe02],
Trojan.BHO, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [d859dc850c70e6503421fae8f30ffe02],
Trojan.BHO, HKU\S-1-5-21-3019136568-2950334141-3358811229-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [d859dc850c70e6503421fae8f30ffe02],
Trojan.BHO, HKU\S-1-5-21-3019136568-2950334141-3358811229-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{FCADDC14-BD46-408A-9842-CDBE1C6D37EB}, Löschen bei Neustart, [d859dc850c70e6503421fae8f30ffe02],
PUP.Optional.SupTab.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [6fc2b2af97e5fd3986ffc50bfa08ab55],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [6fc2b2af97e5fd3986ffc50bfa08ab55],
PUP.Optional.SupTab.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1003-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, Löschen bei Neustart, [6fc2b2af97e5fd3986ffc50bfa08ab55],
PUP.Optional.Delta.A, HKLM\SOFTWARE\delta-homesSoftware, In Quarantäne, [80b1d8890379d066eefbbca662a150b0],
PUP.Optional.NetCrawl.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update NetCrawl, In Quarantäne, [a68b80e15626c07672fe561525de44bc],
PUP.Optional.NetCrawl.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util NetCrawl, In Quarantäne, [250c2f3288f4a492a1d091da5ca7dc24],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginServices, In Quarantäne, [5dd487da85f7ab8b329d71e12bd86c94],
PUP.Optional.NetCrawl.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\NetCrawl, Löschen bei Neustart, [b0812938acd01224f17efa711fe4cd33],
PUP.Optional.RocketFind.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RocketUpdater, Löschen bei Neustart, [e74a273aadcf81b534babb913cc7c33d],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [8ca5520f78042d09c93c8a03f40f0ff1],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [d25f65fce09c44f26eb8b8eb48bc3ec2],
PUP.Optional.Qone8, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{33BB0A4E-99AF-4226-BDF6-49120163DE86}, Löschen bei Neustart, [32ff85dc13694fe76b4b307e3dc7b64a],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0R2Y1I1P1N0J1U1C, Löschen bei Neustart, [d25f65fce09c44f26eb8b8eb48bc3ec2]
Registrierungsdaten: 3
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[41f0b4ad90eca294a4863a2f887d8b75]
PUP.Optional.SweetPage.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.sweet-page.com/?type=sc&ts=1401361416&from=wld&uid=TOSHIBAXTHNS128GG4BAAA-NonFDE_40LS10IPT02Z10IPT02Z, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/?type=sc&ts=1401361416&from=wld&uid=TOSHIBAXTHNS128GG4BAAA-NonFDE_40LS10IPT02Z10IPT02Z),Löschen bei Neustart,[062bcb96017b5adcbdcea5c4a164d62a]
PUP.Optional.Delta.A, HKU\S-1-5-21-3019136568-2950334141-3358811229-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://search.delta-homes.com/web/?type=ds&ts=1402582007&from=wpm0612&uid=TOSHIBAXTHNS128GG4BAAA-NonFDE_40LS10IPT02Z10IPT02Z&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://search.delta-homes.com/web/?type=ds&ts=1402582007&from=wpm0612&uid=TOSHIBAXTHNS128GG4BAAA-NonFDE_40LS10IPT02Z10IPT02Z&q={searchTerms}),Löschen bei Neustart,[d65b98c991ebd95dcb6103671bead32d]
Ordner: 12
PUP.Optional.OpenCandy, C:\Users\Lenovo\AppData\Roaming\OpenCandy, In Quarantäne, [86abe57c225a221446e99782cd360cf4],
PUP.Optional.OpenCandy, C:\Users\Lenovo\AppData\Roaming\OpenCandy\AAA1F53729AC42A6A69A6F507E51BC32, In Quarantäne, [86abe57c225a221446e99782cd360cf4],
PUP.Optional.OpenCandy, C:\Users\Lenovo\AppData\Roaming\OpenCandy\B92C8333E5B0418CACF7B7EB9E335904, In Quarantäne, [86abe57c225a221446e99782cd360cf4],
PUP.Optional.OpenCandy, C:\Users\Lenovo\AppData\Roaming\OpenCandy\EF694C7040AE481AA78B091C2F0533C9, In Quarantäne, [86abe57c225a221446e99782cd360cf4],
PUP.Optional.OpenCandy, C:\Users\Lenovo\AppData\Roaming\OpenCandy\OpenCandy_EF694C7040AE481AA78B091C2F0533C9, In Quarantäne, [86abe57c225a221446e99782cd360cf4],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect, In Quarantäne, [fa37c79a88f41125e0c7bc72b251fb05],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [fa37c79a88f41125e0c7bc72b251fb05],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [fa37c79a88f41125e0c7bc72b251fb05],
PUP.Optional.SupTab.A, C:\Users\Lenovo\AppData\Roaming\SupTab, In Quarantäne, [6ac769f8e19b5cda878eba7dbc47fb05],
PUP.Optional.QueenCoupon.A, C:\ProgramData\QueenCoupon, In Quarantäne, [9e933928df9dba7c7a0593b4b84b37c9],
PUP.Optional.RocketFind.A, C:\Users\Lenovo\AppData\Roaming\RocketUpdater, In Quarantäne, [51e0cb96512b7bbb362f88c15aa9d828],
PUP.Optional.RocketFind.A, C:\Users\Lenovo\AppData\Roaming\RocketUpdater\UpdateProc, In Quarantäne, [51e0cb96512b7bbb362f88c15aa9d828],
Dateien: 8
PUP.Optional.Conduit.A, C:\Users\Lenovo\AppData\Roaming\OpenCandy\AAA1F53729AC42A6A69A6F507E51BC32\sp-downloader.exe, In Quarantäne, [1c154120661633039eda3bfe3dc4b947],
PUP.Optional.OpenCandy, C:\Users\Lenovo\AppData\Roaming\OpenCandy\B92C8333E5B0418CACF7B7EB9E335904\TuneUp2014AUST1day-de-DE-p4v1.exe, In Quarantäne, [86abe57c225a221446e99782cd360cf4],
PUP.Optional.OpenCandy, C:\Users\Lenovo\AppData\Roaming\OpenCandy\EF694C7040AE481AA78B091C2F0533C9\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [86abe57c225a221446e99782cd360cf4],
PUP.Optional.SearchProtect.A, C:\Windows\System32\config\systemprofile\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [fa37c79a88f41125e0c7bc72b251fb05],
PUP.Optional.RocketFind.A, C:\Users\Lenovo\AppData\Roaming\RocketUpdater\UpdateProc\config.dat, In Quarantäne, [51e0cb96512b7bbb362f88c15aa9d828],
PUP.Optional.RocketFind.A, C:\Users\Lenovo\AppData\Roaming\RocketUpdater\UpdateProc\info.dat, In Quarantäne, [51e0cb96512b7bbb362f88c15aa9d828],
PUP.Optional.RocketFind.A, C:\Users\Lenovo\AppData\Roaming\RocketUpdater\UpdateProc\STTL.DAT, In Quarantäne, [51e0cb96512b7bbb362f88c15aa9d828],
PUP.Optional.RocketFind.A, C:\Users\Lenovo\AppData\Roaming\RocketUpdater\UpdateProc\TTL.DAT, In Quarantäne, [51e0cb96512b7bbb362f88c15aa9d828],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
# AdwCleaner v4.105 - Bericht erstellt am 10/12/2014 um 22:58:32
# Aktualisiert 08/12/2014 von Xplode
# Database : 2014-12-08.2 [Live]
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Lenovo - LENOVO-PC
# Gestartet von : C:\Users\Lenovo\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J21B82K8\AdwCleaner_4.105.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : IePluginServices
Dienst Gelöscht : NetControllerService
[#] Dienst Gelöscht : KMService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\ProgramData\e05a3cdb0f5f264c
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software
Ordner Gelöscht : C:\Users\Gast\AppData\Roaming\SuperEasy Software
Ordner Gelöscht : C:\Users\Lenovo\AppData\Local\Rocket
Ordner Gelöscht : C:\Users\Lenovo\AppData\Roaming\337Games
Ordner Gelöscht : C:\Users\Lenovo\AppData\Roaming\NetController
Ordner Gelöscht : C:\Users\Lenovo\AppData\Roaming\SuperEasy Software
Ordner Gelöscht : C:\Users\Lenovo\AppData\Roaming\Software
Ordner Gelöscht : C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
Datei Gelöscht : C:\Windows\system32\srvany.exe
***** [ Tasks ] *****
Task Gelöscht : LaunchSignup
Task Gelöscht : Optimizer Pro Schedule
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Lenovo\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B88824F7-963A-4822-A369-CF6B01C0C36A}
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\SecuredDownload
Schlüssel Gelöscht : HKCU\Software\Vittalia
Schlüssel Gelöscht : HKCU\Software\SuperEasy Software
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\SuperEasy Software
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{779D1843-0043-65D2-D781-8614F17B6222}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetCrawl
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SupTab
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{F6423EE4-93D8-FA04-D09D-A8598F6EFDFD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6C998B44-82D8-CC7E-D847-4CD73036412A}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17420
-\\ Google Chrome v35.0.1916.114
[C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
[C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
[C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : mkcedibhemacmilmkpndpkoidlnmgngg
*************************
AdwCleaner[R0].txt - [8011 octets] - [09/12/2014 20:55:33]
AdwCleaner[R1].txt - [4450 octets] - [10/12/2014 22:57:14]
AdwCleaner[S0].txt - [4820 octets] - [10/12/2014 22:58:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4880 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Professional x86
Ran by Lenovo on 10.12.2014 at 23:05:59,27
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update netcrawl
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util netcrawl
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.12.2014 at 23:08:30,79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-12-2014
Ran by Lenovo (administrator) on LENOVO-PC on 10-12-2014 23:13:37
Running from C:\Users\Lenovo\Downloads
Loaded Profile: Lenovo (Available profiles: Lenovo & EM & Gast)
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
() C:\Program Files\A1 Dashboard\A1Dashboard_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files\A1 Dashboard\A1Dashboard_Launcher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Ricoh co.,Ltd.) C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\ScanToPCActivationApp.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\HPNetworkCommunicator.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2379504 2013-04-24] (Synaptics Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [974432 2014-08-22] (Microsoft Corporation)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [TAG_A1Dashboard_Launcher.exe] => C:\Program Files\A1 Dashboard\A1Dashboard_Launcher.exe [518712 2013-02-04] ()
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-22] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [IMSS] => C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111928 2013-05-03] (Intel Corporation)
HKLM\...\Run: [RotateImage] => C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe [31744 2008-10-30] (Ricoh co.,Ltd.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-11-20] (Adobe Systems Incorporated)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-3019136568-2950334141-3358811229-1000\...\Run: [HP Officejet Pro 8500 A910 (NET)] => C:\Program Files\HP\HP Officejet Pro 8500 A910\Bin\ScanToPCActivationApp.exe [1837672 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3019136568-2950334141-3358811229-1000\...\Run: [AviraSpeedup] => C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe [7609080 2014-12-05] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-18\...\Run: [AviraSpeedup] => C:\Program Files\Avira\AviraSpeedup\avira_system_speedup.exe [7609080 2014-12-05] (Avira Operations GmbH & Co. KG)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3019136568-2950334141-3358811229-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-3019136568-2950334141-3358811229-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.254 213.33.99.70
Tcpip\..\Interfaces\{160EDFFE-8340-42B9-89C6-2E46E259EE8D}: [NameServer] 194.48.128.199 194.48.139.254
Tcpip\..\Interfaces\{396CEC69-F7AE-4DA5-BC69-D9B9DA877548}: [NameServer] 194.48.139.254 194.48.128.199
Tcpip\..\Interfaces\{601D3111-7752-4509-85AC-25A81C528530}: [NameServer] 194.48.139.254 194.48.128.199
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_246.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF StartMenuInternet: FIREFOX.EXE - C:\Users\Gast\AppData\Local\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR Profile: C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-05]
CHR Extension: (Google Drive) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-05]
CHR Extension: (YouTube) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-05]
CHR Extension: (Google-Suche) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-05]
CHR Extension: (Google Wallet) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-05]
CHR Extension: (Google Mail) - C:\Users\Lenovo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-05]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc7.exe [806704 2014-10-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [432888 2014-10-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [432888 2014-10-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe [995064 2014-10-22] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22192 2014-08-22] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [288120 2014-08-22] (Microsoft Corporation)
R2 TAG_Service; C:\Program Files\A1 Dashboard\A1Dashboard_Service.exe [334392 2013-02-04] ()
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-07-23] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [37384 2014-10-09] (Avira Operations GmbH & Co. KG)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [89856 2011-09-09] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2011-09-09] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [186880 2011-09-09] (Huawei Technologies Co., Ltd.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231800 2014-07-17] (Microsoft Corporation)
R1 ncdevice; C:\Windows\System32\DRIVERS\ncdevice.sys [35616 2014-05-26] (NT Kernel Resources)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [25328 2014-06-16] (Synaptics Incorporated)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-07-23] (Avira GmbH)
S3 catchme; \??\C:\Users\Lenovo\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-10 23:08 - 2014-12-10 23:08 - 00000882 _____ () C:\Users\Lenovo\Desktop\JRT.txt
2014-12-10 23:05 - 2014-12-10 23:05 - 00000000 ____D () C:\Windows\ERUNT
2014-12-10 23:04 - 2014-12-10 23:05 - 01707646 _____ (Thisisu) C:\Users\Lenovo\Downloads\JRT.exe
2014-12-10 23:02 - 2014-12-10 23:02 - 00004960 _____ () C:\Users\Lenovo\Downloads\AdwCleaner[S0].txt
2014-12-10 22:56 - 2014-12-10 22:56 - 02166272 _____ () C:\Users\Lenovo\Downloads\AdwCleaner_4.105 (1).exe
2014-12-10 22:55 - 2014-12-10 22:55 - 00010396 _____ () C:\Users\Lenovo\Desktop\mbam.txt
2014-12-10 22:36 - 2014-12-10 22:53 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-10 22:36 - 2014-12-10 22:36 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-10 22:36 - 2014-12-10 22:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-10 22:36 - 2014-12-10 22:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-10 22:36 - 2014-12-10 22:36 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-12-10 22:36 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-10 22:36 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-10 22:36 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-10 22:34 - 2014-12-10 22:35 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Lenovo\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-09 23:07 - 2014-12-09 23:07 - 00020631 _____ () C:\ComboFix.txt
2014-12-09 22:58 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-09 22:58 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-09 22:58 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-09 22:58 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-09 22:58 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-09 22:58 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-09 22:58 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-09 22:58 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-09 22:55 - 2014-12-09 23:07 - 00000000 ____D () C:\Qoobox
2014-12-09 22:55 - 2014-12-09 23:06 - 00000000 ____D () C:\Windows\erdnt
2014-12-09 22:53 - 2014-12-09 22:54 - 05601243 ____R (Swearware) C:\Users\Lenovo\Desktop\ComboFix.exe
2014-12-09 22:40 - 2014-12-09 22:40 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Lenovo\Downloads\revosetup95.exe
2014-12-09 22:40 - 2014-12-09 22:40 - 00001226 _____ () C:\Users\Lenovo\Desktop\Revo Uninstaller.lnk
2014-12-09 22:40 - 2014-12-09 22:40 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-12-09 21:19 - 2014-12-09 21:19 - 00053782 _____ () C:\Users\Lenovo\Desktop\Ereignisse.txt
2014-12-09 21:15 - 2014-12-09 21:15 - 00005997 _____ () C:\Users\Lenovo\Desktop\gmer.log
2014-12-09 21:04 - 2014-12-09 21:04 - 00380416 _____ () C:\Users\Lenovo\Downloads\Gmer-19357.exe
2014-12-09 21:03 - 2014-12-09 21:03 - 00025176 _____ () C:\Users\Lenovo\Desktop\Addition.txt
2014-12-09 21:01 - 2014-12-10 23:13 - 00011780 _____ () C:\Users\Lenovo\Downloads\FRST.txt
2014-12-09 21:01 - 2014-12-09 21:01 - 00025176 _____ () C:\Users\Lenovo\Downloads\Addition.txt
2014-12-09 21:00 - 2014-12-10 23:13 - 00000000 ____D () C:\FRST
2014-12-09 20:59 - 2014-12-09 21:00 - 01111040 _____ (Farbar) C:\Users\Lenovo\Downloads\FRST.exe
2014-12-09 20:56 - 2014-12-09 20:57 - 00000474 _____ () C:\Users\Lenovo\Desktop\defogger_disable.log
2014-12-09 20:56 - 2014-12-09 20:56 - 00050477 _____ () C:\Users\Lenovo\Downloads\Defogger.exe
2014-12-09 20:56 - 2014-12-09 20:56 - 00000000 _____ () C:\Users\Lenovo\defogger_reenable
2014-12-09 20:48 - 2014-12-10 22:58 - 00000000 ____D () C:\AdwCleaner
2014-12-09 20:48 - 2014-12-09 20:48 - 02166272 _____ () C:\Users\Lenovo\Downloads\AdwCleaner_4.105.exe
2014-12-09 19:47 - 2014-12-09 20:11 - 00000000 ____D () C:\Users\Gast\AppData\Local\Mozilla Firefox
2014-12-05 17:19 - 2014-12-05 17:19 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-12-05 08:58 - 2014-12-05 08:59 - 06053704 _____ (TeamViewer) C:\Users\Lenovo\Downloads\TOGETHER_Fernwartung_vers903.exe
2014-12-05 08:37 - 2014-12-05 08:37 - 00002197 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-05 08:37 - 2014-12-05 08:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-12-05 08:36 - 2014-12-10 23:00 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-05 08:36 - 2014-12-10 22:42 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-05 08:36 - 2014-12-09 23:05 - 00000000 ____D () C:\Program Files\Google
2014-12-05 08:36 - 2014-12-09 20:30 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-12-05 08:36 - 2014-12-05 08:36 - 00001989 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2014-12-05 08:35 - 2014-12-05 08:35 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-12-01 20:38 - 2014-12-10 22:59 - 00016310 _____ () C:\Windows\PFRO.log
2014-11-22 09:24 - 2014-12-10 22:59 - 00001176 _____ () C:\Windows\setupact.log
2014-11-22 09:24 - 2014-11-22 09:24 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-19 17:36 - 2014-11-11 03:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 17:36 - 2014-11-11 03:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-16 12:41 - 2010-07-28 19:36 - 00107776 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbser6k.sys
2014-11-16 12:41 - 2010-07-28 19:36 - 00107776 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbnmea.sys
2014-11-16 12:41 - 2010-07-27 18:25 - 00116736 _____ (ZTE Corporation) C:\Windows\system32\Drivers\ZTEusbnet.sys
2014-11-16 12:40 - 2014-11-16 12:41 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\TAG
2014-11-16 12:40 - 2014-11-16 12:40 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Sierra Wireless
2014-11-16 12:40 - 2010-07-28 19:36 - 00107776 _____ (ZTE Incorporated) C:\Windows\system32\Drivers\ZTEusbmdm6k.sys
2014-11-16 12:40 - 2010-04-14 17:58 - 00009216 _____ (MBB Incorporated) C:\Windows\system32\Drivers\massfilter.sys
2014-11-14 23:39 - 2014-11-14 23:39 - 00001165 _____ () C:\Users\Lenovo\Desktop\Avira System Speedup.lnk
2014-11-14 23:39 - 2014-11-14 23:39 - 00001165 _____ () C:\Users\Gast\Desktop\Avira System Speedup.lnk
2014-11-14 23:39 - 2014-11-14 23:39 - 00001165 _____ () C:\Users\EM\Desktop\Avira System Speedup.lnk
2014-11-14 23:36 - 2014-11-14 23:36 - 00000000 __SHD () C:\Users\Lenovo\AppData\Local\EmieBrowserModeList
2014-11-14 17:04 - 2014-11-14 17:04 - 00000000 __SHD () C:\Users\Gast\AppData\Local\EmieBrowserModeList
2014-11-14 16:34 - 2014-11-05 21:29 - 583364528 _____ () C:\Users\Gast\Desktop\Bernd 3.tif
2014-11-14 16:34 - 2014-11-05 21:28 - 615919740 _____ () C:\Users\Gast\Desktop\Bernd 2.tif
2014-11-14 16:34 - 2014-11-05 21:28 - 571142964 _____ () C:\Users\Gast\Desktop\Bernd 1.tif
2014-11-14 16:33 - 2014-11-05 21:31 - 553540420 _____ () C:\Users\Gast\Desktop\Bernd 4.tif
2014-11-12 22:22 - 2014-11-07 20:23 - 00341168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-12 22:22 - 2014-11-06 04:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-12 22:22 - 2014-11-06 04:28 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-12 22:22 - 2014-11-06 04:13 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-12 22:22 - 2014-11-06 04:13 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-12 22:22 - 2014-11-06 04:12 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-12 22:22 - 2014-11-06 04:10 - 19781632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-12 22:22 - 2014-11-06 04:10 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-12 22:22 - 2014-11-06 04:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-12 22:22 - 2014-11-06 04:04 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-12 22:22 - 2014-11-06 04:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-12 22:22 - 2014-11-06 04:00 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-12 22:22 - 2014-11-06 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-12 22:22 - 2014-11-06 03:59 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-12 22:22 - 2014-11-06 03:58 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-12 22:22 - 2014-11-06 03:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-12 22:22 - 2014-11-06 03:48 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-12 22:22 - 2014-11-06 03:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-12 22:22 - 2014-11-06 03:37 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-12 22:22 - 2014-11-06 03:36 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-12 22:22 - 2014-11-06 03:34 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-12 22:22 - 2014-11-06 03:22 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-12 22:22 - 2014-11-06 03:22 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-12 22:22 - 2014-11-06 03:21 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-12 22:22 - 2014-11-06 03:21 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-12 22:22 - 2014-11-06 03:20 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-12 22:22 - 2014-11-06 03:03 - 12819456 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-12 22:22 - 2014-11-06 02:52 - 01892864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-12 22:22 - 2014-11-06 02:48 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-12 22:22 - 2014-11-06 02:47 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-12 22:22 - 2014-11-05 18:50 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-12 22:22 - 2014-11-05 18:50 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-12 22:22 - 2014-11-05 18:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-12 22:22 - 2014-10-25 02:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-12 22:22 - 2014-10-18 02:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-12 22:22 - 2014-10-14 02:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-12 22:22 - 2014-10-14 02:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-12 22:22 - 2014-10-14 02:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-12 22:22 - 2014-10-14 02:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-12 22:22 - 2014-10-14 02:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-12 22:22 - 2014-10-14 02:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-12 22:22 - 2014-10-10 01:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-12 22:22 - 2014-10-03 02:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-12 22:22 - 2014-10-03 02:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-12 22:22 - 2014-10-03 02:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-12 22:22 - 2014-10-03 02:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-12 22:22 - 2014-10-03 02:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-12 22:22 - 2014-09-19 10:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-12 22:22 - 2014-09-19 10:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-12 22:22 - 2014-09-19 10:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-12 22:22 - 2014-09-19 10:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-12 22:22 - 2014-09-19 10:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-12 22:22 - 2014-09-19 10:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-12 22:22 - 2014-08-21 07:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-12 22:22 - 2014-08-21 07:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-12 22:22 - 2014-08-12 02:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-10 23:06 - 2009-07-14 05:34 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-10 23:06 - 2009-07-14 05:34 - 00031312 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-10 23:04 - 2010-11-20 22:01 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-10 23:02 - 2014-05-18 10:00 - 01738098 _____ () C:\Windows\WindowsUpdate.log
2014-12-10 23:01 - 2014-08-20 13:54 - 00001095 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-12-10 23:01 - 2014-08-20 13:54 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-10 23:01 - 2014-08-20 13:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-12-10 23:01 - 2014-08-20 13:52 - 00000000 ____D () C:\Program Files\Avira
2014-12-10 22:59 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-10 22:59 - 2009-07-14 05:33 - 00409064 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-10 22:58 - 2014-05-18 10:00 - 00001154 _____ () C:\Users\Lenovo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-10 22:53 - 2014-11-09 19:15 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\AviraSpeedup
2014-12-10 22:53 - 2014-05-18 12:29 - 00109680 _____ () C:\Users\Lenovo\AppData\Local\GDIPFONTCACHEV1.DAT
2014-12-10 22:52 - 2014-11-08 22:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviraSpeedup
2014-12-10 22:50 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\security
2014-12-10 22:48 - 2014-06-20 16:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-09 23:07 - 2009-07-14 03:37 - 00000000 __RHD () C:\Users\Default
2014-12-09 23:07 - 2009-07-14 03:37 - 00000000 ___RD () C:\Users\Public
2014-12-09 23:06 - 2009-07-14 03:04 - 00000215 _____ () C:\Windows\system.ini
2014-12-09 22:06 - 2014-11-08 22:19 - 00000000 ___RD () C:\Users\Gast\Dropbox
2014-12-09 22:06 - 2014-11-08 22:10 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Dropbox
2014-12-09 20:56 - 2014-05-18 10:00 - 00000000 ____D () C:\Users\Lenovo
2014-12-09 20:43 - 2014-05-27 17:50 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Media Player Classic
2014-12-09 20:31 - 2014-08-29 12:19 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Google
2014-12-09 18:48 - 2014-06-20 16:43 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-12-09 18:48 - 2014-06-20 16:43 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-12-05 21:01 - 2014-05-29 09:36 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Adobe
2014-12-05 09:34 - 2014-05-27 16:11 - 00000000 ____D () C:\ProgramData\Adobe
2014-12-05 09:26 - 2014-05-30 10:22 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\TeamViewer
2014-12-05 08:51 - 2014-06-25 08:58 - 00000000 ____D () C:\Users\Lenovo\AppData\Local\Adobe
2014-12-05 08:51 - 2014-05-18 12:00 - 00000000 ____D () C:\Users\Lenovo\AppData\Roaming\Adobe
2014-12-05 08:50 - 2014-07-25 21:16 - 00000000 ____D () C:\ProgramData\TEMP
2014-12-05 08:35 - 2014-05-27 16:11 - 00000000 ____D () C:\Program Files\Adobe
2014-11-15 18:10 - 2014-10-11 16:33 - 00000000 ____D () C:\Windows\Minidump
2014-11-15 15:04 - 2014-11-08 22:19 - 00001015 _____ () C:\Users\Gast\Desktop\Dropbox.lnk
2014-11-15 15:04 - 2014-11-08 22:18 - 00000000 ____D () C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-11-13 22:29 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache
2014-11-13 21:59 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-11-13 15:24 - 2014-05-29 09:36 - 00109280 _____ () C:\Users\Gast\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-13 15:20 - 2014-05-18 11:57 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-13 15:20 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-11-12 22:59 - 2014-05-20 18:37 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-11-12 22:56 - 2014-05-18 10:57 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-12 22:54 - 2014-05-18 10:57 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
Some content of TEMP:
====================
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
C:\Users\Lenovo\AppData\Local\Temp\avgnt.exe
C:\Users\Lenovo\AppData\Local\Temp\AviraSetup116423.exe
C:\Users\Lenovo\AppData\Local\Temp\Quarantine.exe
C:\Users\Lenovo\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-05 09:17
==================== End Of Log ============================ --- --- --- |