nightflight | 29.01.2015 13:25 | Malwarebytes: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.01.2015
Suchlauf-Zeit: 10:37:26
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.29.05
Rootkit Datenbank: v2015.01.14.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: nightflight
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 366792
Verstrichene Zeit: 12 Min, 17 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 6
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, In Quarantäne, [2dfcdc218cfdd462217941ef53b06a96],
PUP.Optional.Babylon.A, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [d059ab521178f145e648ed0ac53db44c],
PUP.Optional.DataMngr.A, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\DataMngr_Toolbar, In Quarantäne, [a3860eef32571f17a9ec05d515ef629e],
PUP.Optional.OfferMosquito.A, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\OfferMosquito, In Quarantäne, [0a1f03faa0e9ee4810b66799d92c40c0],
PUP.Optional.OfferMosquito.A, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\gbmdkmlcnbapgegninelmjbfibaghdmk, In Quarantäne, [b673916c6b1e270f1489f7b5bf44c33d],
PUP.Optional.BProtector.A, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\bProtectSettings, In Quarantäne, [19106994f099a78fe6f6e1fc9371a65a],
Registrierungswerte: 2
PUP.BProtector, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|bProtector Start Page, hxxp://www2.delta-search.com/?babsrc=HP_ss&mntrId=7863F67BCB2C4A1A&affID=121564&tsp=4987, In Quarantäne, [c366da23a7e265d10790c317ea1a7c84]
PUP.BProtector, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|bProtectorDefaultScope, {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, In Quarantäne, [e2471de07e0bdf57a6f29c3efa0aaf51]
Registrierungsdaten: 1
Hijack.StartPage, HKU\S-1-5-21-1072828290-3828818215-1948454868-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.doko-search.com/?babsrc=HP_ss_mib2&mntrId=7863F67BCB2C4A1A&affID=121564&tsp=4987, Gut: (www.google.com), Schlecht: (hxxp://www.doko-search.com/?babsrc=HP_ss_mib2&mntrId=7863F67BCB2C4A1A&affID=121564&tsp=4987),Ersetzt,[999016e78702c076740aa504f1146e92]
Ordner: 9
PUP.Optional.OpenCandy, C:\Users\nightflight\AppData\Roaming\OpenCandy, In Quarantäne, [d554619c9fea34026d3f85bf7c874eb2],
PUP.Optional.OpenCandy, C:\Users\nightflight\AppData\Roaming\OpenCandy\3E84235A361147EF88E0F41604352755, In Quarantäne, [d554619c9fea34026d3f85bf7c874eb2],
PUP.Optional.OpenCandy, C:\Users\nightflight\AppData\Roaming\OpenCandy\40515EB26DFC45B49949B2565B8B0EB5, In Quarantäne, [d554619c9fea34026d3f85bf7c874eb2],
PUP.Optional.OpenCandy, C:\Users\nightflight\AppData\Roaming\OpenCandy\5213415FA8DB49C487B9DD0D9BA7A547, In Quarantäne, [d554619c9fea34026d3f85bf7c874eb2],
PUP.Optional.OpenCandy, C:\Users\nightflight\AppData\Roaming\OpenCandy\B4786E8F0E014F3A96BF1397E1966E70, In Quarantäne, [d554619c9fea34026d3f85bf7c874eb2],
PUP.Optional.OpenCandy, C:\Users\nightflight\AppData\Roaming\OpenCandy\BCC66A1F127C44CDADA9909DE6A65D96, In Quarantäne, [d554619c9fea34026d3f85bf7c874eb2],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\extensions\gbmdkmlcnbapgegninelmjbfibaghdmk, In Quarantäne, [ab7ee716b7d20e28a7d70f44be452dd3],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\1.2_1, In Quarantäne, [ab7ee716b7d20e28a7d70f44be452dd3],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\ext_offermosquito, In Quarantäne, [5acf3fbe2d5cb6807708074c37ccc739],
Dateien: 41
PUP.Optional.Babylon.A, C:\Users\nightflight\AppData\Roaming\OpenCandy\BCC66A1F127C44CDADA9909DE6A65D96\DeltaTB.exe, In Quarantäne, [0821cf2ea9e0d85e726e4ddd4cb533cd],
PUP.Optional.BrowserDefender.A, C:\Windows\System32\Tasks\BrowserDefendert, In Quarantäne, [63c608f5b2d770c669f5b2f025de817f],
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\searchplugins\softonic.xml, In Quarantäne, [74b53ebfb1d868ce976d7d3a966dcc34],
PUP.Optional.BProtector.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\bProtector_extensions.sqlite, In Quarantäne, [46e385783653bc7a09f58f2a7093758b],
PUP.Optional.BProtector.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\bProtector_prefs.js, In Quarantäne, [fa2f629b50396ec827d85e5b897a669a],
PUP.Optional.OpenCandy, C:\Users\nightflight\AppData\Roaming\OpenCandy\B4786E8F0E014F3A96BF1397E1966E70\Trial-14.0.1000.89_de-DE_1004732_DE-1.exe, In Quarantäne, [d554619c9fea34026d3f85bf7c874eb2],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\1.2_1\dependencies.js, In Quarantäne, [ab7ee716b7d20e28a7d70f44be452dd3],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\1.2_1\events.js, In Quarantäne, [ab7ee716b7d20e28a7d70f44be452dd3],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\1.2_1\icon.png, In Quarantäne, [ab7ee716b7d20e28a7d70f44be452dd3],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\1.2_1\manifest.json, In Quarantäne, [ab7ee716b7d20e28a7d70f44be452dd3],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\extensions\gbmdkmlcnbapgegninelmjbfibaghdmk\1.2_1\offermosquito.js, In Quarantäne, [ab7ee716b7d20e28a7d70f44be452dd3],
PUP.Optional.OfferMosquito.A, C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\ext_offermosquito\ext_offermosquito.crx, In Quarantäne, [5acf3fbe2d5cb6807708074c37ccc739],
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.admin", false);), Ersetzt,[e8415ba208811e182bfa796cb3520000]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
), Ersetzt,[47e20cf1becbcf67dc498065ce370ff1]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (references
/* Do not edit this file.
*
* If you make changes to this file ), Ersetzt,[2306eb12f8919e986cb9707557aef10f]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (e.
*
* If you make changes to this file while t), Ersetzt,[25049964c3c643f349dcfbea8085b848]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you), Ersetzt,[9693dd20deab3303929331b4d530f907]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (erences
/* Do not edit this file.
*
* If ), Ersetzt,[0c1dd22b464363d3d0557c699e67669a]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (rences
/* Do not edit this file.
*
* If), Ersetzt,[60c940bd8aff6ccad05540a548bd18e8]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
* If), Ersetzt,[d158bc416b1eb581d84d984d6c99f30d]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (rences
/* Do not edit this file.
*
* If you m), Ersetzt,[38f156a7325768ce51d4687da560ef11]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (es
/* Do not edit this file.
*
* If y), Ersetzt,[29001ce1f495e6503bea9550ec197e82]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (references
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be ove), Ersetzt,[e841d5280c7d60d651d444a1d332bf41]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (tion is running,
* the changes will be overwritten when the applicatio), Ersetzt,[67c2936a0c7d89ad5cc9af36a461ef11]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: ( this file.
*
* If you make changes to this fil), Ersetzt,[f7329568751480b628fd717432d39769]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you make c), Ersetzt,[35f4c23bf99044f2899c766fe81d19e7]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (
/* Do not edit this file.
*
* If you m), Ersetzt,[270253aa1b6e0333e93c9451df26748c]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwrit), Ersetzt,[bf6a708db1d8e05603228f567e87d22e]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (n is running,
* the changes will be overwritten w), Ersetzt,[1e0b2cd1dfaad561879ef5f0fe07738d]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you make ), Ersetzt,[3fea02fb51382b0bcb5ac52013f24cb4]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (s
/* Do not edit this file.
*
* If you m), Ersetzt,[2900a657d2b7be78b1743baa38cde818]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (erences
/* Do not edit this file.
*
* If y), Ersetzt,[0821d825721782b4d253677e2adb2ad6]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ences
/* Do not edit this file.
*
* If you make changes to this f), Ersetzt,[97929f5e1772a4920f16578e6a9b966a]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: ( this file.
*
* If you make changes to this file whil), Ersetzt,[57d26b92d0b90d2924017d68e0250ff1]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the a), Ersetzt,[61c8817c24654fe7cf5608dddf2657a9]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (s running,
* the changes will be overwritten when), Ersetzt,[979266975039b38327fe6f7655b0659b]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ces
/* Do not edit this file.
*
* If you make changes ), Ersetzt,[a08917e6d3b64ee8e44117ce35d07789]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (Do not edit this file.
*
* If you make changes t), Ersetzt,[f336ae4fccbd96a068bdb03539ccaa56]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=78635dfc000000000000f67bcb2c4a1a");), Ersetzt,[a287ed108ffade5868c5b03560a59b65]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (ity.typeaheadfind.flashBar", 0);
user_pref("app.update.lastUpdateTime.addon-background-update-timer", 1422439520);
user_pref("app.update.lastUp), Ersetzt,[c26715e8abde43f304297c69ca3b6a96]
PUP.Optional.Softonic.A, C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\prefs.js, Gut: (), Schlecht: (20);
user_pref("app.update.lastUpdateTime.background-update-timer", 1422487941);
user_pref("app.update.lastUpdateTime.blocklist-background-update-), Ersetzt,[42e7b6475930ae88f7363baa60a51ae6]
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end)
Adw Cleaner: Code:
# AdwCleaner v4.109 - Bericht erstellt am 29/01/2015 um 12:08:46
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-01-26.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : nightflight - NIGHTFLIGHT-PC
# Gestartet von : C:\Users\nightflight\Desktop\AdwCleaner_4.109.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\Program Files\AVG Secure Search
Ordner Gelöscht : C:\Program Files\AVG Security Toolbar
Ordner Gelöscht : C:\Users\nightflight\AppData\LocalLow\Softonic
Ordner Gelöscht : C:\Users\nightflight\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\nightflight\AppData\Roaming\fbDownloader
Ordner Gelöscht : C:\Users\nightflight\AppData\Roaming\Intermediate
Ordner Gelöscht : C:\Users\nightflight\AppData\Roaming\SCheck
Ordner Gelöscht : C:\Users\nightflight\AppData\Roaming\Snz
Ordner Gelöscht : C:\Users\nightflight\AppData\Roaming\SSync
Datei Gelöscht : C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\bProtector_extensions.rdf
Datei Gelöscht : C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\invalidprefs.js
Datei Gelöscht : C:\Program Files\Mozilla Firefox\browser\searchplugins\avg-secure-search.xml
Datei Gelöscht : C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\searchplugins\fbdownloader_search.xml
Datei Gelöscht : C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\user.js
***** [ Tasks ] *****
Task Gelöscht : BrowserDefendert
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Intermediate]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [scheck]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Snoozer]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ssync]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\5ced8dab168ba12
Schlüssel Gelöscht : HKLM\SOFTWARE\5ced8dab168ba12
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{D91ED387-0BD8-4597-9EEB-799ABBAF73D9}
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Protector
Schlüssel Gelöscht : HKLM\SOFTWARE\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\ICQ\ICQToolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\43C098337DB065A49B665D4EA7F16D1C
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A71991503412AEB42838B02C5ED9F9CD
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v35.0.1 (x86 de)
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q=");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.admin", false);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.aflt", "OC");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.appId", "{7ABBFE1C-E485-44AA-8F36-353751B4124D}");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.autoRvrt", "false");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dfltLng", "de");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dfltSrch", true);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.dnsErr", true);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.excTlbr", false);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.ffxUnstlRst", false);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hmpg", true);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.hmpgUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=13&cc=&mi=78635dfc000000000000f67bcb2c4a1a");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.id", "78635dfc000000000000f67bcb2c4a1a");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.instlDay", "16059");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.instlRef", "MOY00621");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.newTab", true);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.newTabUrl", "hxxp://search.softonic.com/MOY00621/tb_v1/?SearchSource=15&cc=&mi=78635dfc000000000000f67bcb2c4a1a");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.prdct", "Softonic");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.prtnrId", "softonic");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.rvrt", "false");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.smplGrp", "none");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.srchPrvdr", "Search the web (Softonic)");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.tlbrId", "opencandy2013");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.tlbrSrchUrl", "hxxp://search.softonic.com/MOY00621/tb_v1?SearchSource=1&cc=&mi=78635dfc000000000000f67bcb2c4a1a&q=");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.vrsn", "1.8.21.14");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.vrsnTs", "1.8.21.1415:35:44");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.Softonic.vrsni", "1.8.21.14");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.admin", false);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.aflt", "babsst");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.autoRvrt", "false");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.dfltLng", "de");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.excTlbr", false);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.id", "78635dfc000000000000f67bcb2c4a1a");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.instlDay", "15944");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.instlRef", "sst");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.newTab", false);
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.prdct", "delta");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.prtnrId", "delta");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.rvrt", "false");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.smplGrp", "none");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.tlbrId", "base");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.613:22:19");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta_i.babExt", "");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta_i.babTrack", "affID=121564&tsp=4987");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
[ewgkopok.default\prefs.js] - Zeile gelöscht : user_pref("simplenewtab.url", "hxxp://wisersearch.com/?channel=de_nt");
-\\ Google Chrome v40.0.2214.93
*************************
AdwCleaner[R0].txt - [10726 octets] - [29/01/2015 11:46:20]
AdwCleaner[S0].txt - [11105 octets] - [29/01/2015 12:08:46]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11166 octets] ##########
Junkware Removal Tool: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 7 Home Premium x86
Ran by nightflight on 29.01.2015 at 12:17:22,11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\nightflight\AppData\Roaming\mozilla\firefox\profiles\ewgkopok.default\minidumps [77 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.01.2015 at 12:25:59,30
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
neues FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 28-01-2015 01
Ran by nightflight (administrator) on NIGHTFLIGHT-PC on 29-01-2015 12:30:56
Running from C:\Users\nightflight\Desktop\Troja
Loaded Profiles: nightflight (Available profiles: nightflight)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgrsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgcsrvx.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX86\officeclicktorun.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgnsx.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgemcx.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(AlcaTech) C:\Windows\System32\mmrtkrnl.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2015\avgui.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(SEC) C:\Program Files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [8092192 2009-11-21] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1578280 2009-10-10] (Synaptics Incorporated)
HKLM\...\Run: [Realtime Audio Engine] => "mmrtkrnl.exe" /i
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM\...\Run: [AVG_UI] => C:\Program Files\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\...\Run: [Personal ID] => C:\Program Files\coolspot AG\Personal ID\pid.exe [1132984 2011-12-11] (coolspot AG, Düsseldorf)
HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1072828290-3828818215-1948454868-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1072828290-3828818215-1948454868-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7SMSN_deDE392
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKU\S-1-5-21-1072828290-3828818215-1948454868-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1072828290-3828818215-1948454868-1000 -> No Name - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - No File
Toolbar: HKU\S-1-5-21-1072828290-3828818215-1948454868-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} hxxp://esupport.epson-europe.com/selftest/de/Prg/ESTPTest.cab
DPF: {C345E174-3E87-4F41-A01C-B066A90A49B4} hxxp://trial.trymicrosoftoffice.com/trialoaa/buymsoffice_assets/framework//microsoft/wrc32.ocx
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1072828290-3828818215-1948454868-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\nightflight\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\searchplugins\kikin-search.xml
FF Extension: YouTube Unblocker - C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\Extensions\youtubeunblocker@unblocker.yt [2014-11-05]
FF Extension: {44e7b5ce-7ea2-4276-b58f-7f2bcefcf5dd} - C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\Extensions\{44e7b5ce-7ea2-4276-b58f-7f2bcefcf5dd}.xpi [2013-11-19]
FF Extension: Adblock Plus - C:\Users\nightflight\AppData\Roaming\Mozilla\Firefox\Profiles\ewgkopok.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-06-02]
Chrome:
=======
CHR Profile: C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-08]
CHR Extension: (Google Wallet) - C:\Users\nightflight\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-26]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVGIDSAgent; C:\Program Files\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX86\OfficeClickToRun.exe [1679536 2014-11-11] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 OberonGameConsoleService; C:\Program Files\Samsung Casual Games\GameConsole\OberonGameConsoleService.exe [44312 2009-08-13] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R1 Avgdiskx; C:\windows\System32\DRIVERS\avgdiskx.sys [121624 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\windows\System32\DRIVERS\avgidsdriverx.sys [208152 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHX; C:\windows\System32\DRIVERS\avgidshx.sys [154904 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSShim; C:\windows\System32\DRIVERS\avgidsshimx.sys [21272 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx86; C:\windows\System32\DRIVERS\avgldx86.sys [192792 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avglogx; C:\windows\System32\DRIVERS\avglogx.sys [230680 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx86; C:\windows\System32\DRIVERS\avgmfx86.sys [98584 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx86; C:\windows\System32\DRIVERS\avgrkx86.sys [27416 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdix; C:\windows\System32\DRIVERS\avgtdix.sys [200984 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 dtsoftbus01; C:\windows\System32\DRIVERS\dtsoftbus01.sys [242240 2014-11-28] (DT Soft Ltd)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-29] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R3 yukonw7; C:\windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\NIGHTF~1\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-29 12:26 - 2015-01-29 12:29 - 00000769 _____ () C:\Users\nightflight\Desktop\JRT.txt
2015-01-29 12:17 - 2015-01-29 12:17 - 00000000 ____D () C:\windows\ERUNT
2015-01-29 12:16 - 2015-01-29 12:16 - 01707939 _____ (Thisisu) C:\Users\nightflight\Desktop\JRT.exe
2015-01-29 12:14 - 2015-01-29 12:14 - 00011247 _____ () C:\Users\nightflight\Desktop\AdwCleaner[S0].txt
2015-01-29 11:46 - 2015-01-29 12:08 - 00000000 ____D () C:\AdwCleaner
2015-01-29 11:42 - 2015-01-29 11:42 - 02194432 _____ () C:\Users\nightflight\Desktop\AdwCleaner_4.109.exe
2015-01-29 11:36 - 2015-01-29 11:36 - 00014453 _____ () C:\Users\nightflight\Desktop\mbam.txt
2015-01-29 10:36 - 2015-01-29 12:12 - 00114904 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-01-29 10:35 - 2015-01-29 10:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-29 10:35 - 2015-01-29 10:35 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-01-29 10:35 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2015-01-29 10:35 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2015-01-29 10:35 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2015-01-29 10:33 - 2015-01-29 10:33 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\nightflight\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-28 12:53 - 2015-01-28 12:53 - 00020377 _____ () C:\ComboFix.txt
2015-01-28 12:27 - 2015-01-28 12:28 - 05610841 ____R (Swearware) C:\Users\nightflight\Desktop\ComboFix.exe
2015-01-28 10:10 - 2015-01-28 10:10 - 00160192 _____ () C:\windows\Minidump\012815-48578-01.dmp
2015-01-28 10:09 - 2015-01-28 10:09 - 350151229 _____ () C:\windows\MEMORY.DMP
2015-01-28 09:58 - 2015-01-29 12:30 - 00000000 ____D () C:\Users\nightflight\Desktop\Troja
2015-01-28 09:53 - 2015-01-29 12:30 - 00000000 ____D () C:\FRST
2015-01-27 01:38 - 2015-01-27 01:38 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-01-14 07:11 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-01-14 07:11 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxdav.sys
2015-01-14 07:11 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\windows\system32\ntkrnlpa.exe
2015-01-14 07:11 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-01-14 07:11 - 2014-12-11 18:47 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\TSWbPrxy.exe
2015-01-14 07:11 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\windows\system32\nlasvc.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-29 12:18 - 2009-07-14 05:34 - 00023328 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-01-29 12:18 - 2009-07-14 05:34 - 00023328 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-01-29 12:14 - 2010-08-10 16:45 - 00001098 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-01-29 12:10 - 2014-11-11 17:07 - 00060694 _____ () C:\windows\PFRO.log
2015-01-29 12:10 - 2014-10-18 17:55 - 00005288 _____ () C:\windows\setupact.log
2015-01-29 12:10 - 2009-07-14 05:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2015-01-29 12:09 - 2009-12-05 00:54 - 01723254 _____ () C:\windows\WindowsUpdate.log
2015-01-29 12:00 - 2013-08-08 12:20 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2015-01-29 11:38 - 2009-07-14 03:37 - 00000000 ____D () C:\windows\Branding
2015-01-29 10:35 - 2013-06-12 20:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-29 10:21 - 2013-08-18 23:33 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-29 00:34 - 2014-03-31 14:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-29 00:33 - 2013-11-23 12:28 - 00000952 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1072828290-3828818215-1948454868-1000UA.job
2015-01-29 00:08 - 2012-05-17 21:18 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-01-28 12:53 - 2013-06-12 19:04 - 00000000 ____D () C:\Qoobox
2015-01-28 12:50 - 2009-07-14 03:04 - 00000215 _____ () C:\windows\system.ini
2015-01-28 12:49 - 2013-06-11 20:43 - 00000000 ____D () C:\Users\nightflight\AppData\Roaming\Common
2015-01-28 12:33 - 2013-11-23 12:28 - 00000930 _____ () C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1072828290-3828818215-1948454868-1000Core.job
2015-01-28 10:15 - 2011-12-05 14:07 - 00000000 ____D () C:\Users\nightflight\AppData\Local\CrashDumps
2015-01-28 10:10 - 2011-01-24 17:03 - 00000000 ____D () C:\windows\Minidump
2015-01-28 09:50 - 2013-06-11 21:16 - 00000166 _____ () C:\Users\nightflight\defogger_reenable
2015-01-28 09:42 - 2014-02-26 18:33 - 00002121 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-01-24 21:33 - 2013-06-14 20:37 - 00701616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2015-01-24 21:33 - 2013-06-14 20:37 - 00071344 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2015-01-15 07:07 - 2013-08-15 12:00 - 00000000 ____D () C:\windows\system32\MRT
2015-01-15 06:58 - 2010-09-01 13:01 - 110348472 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-01-10 21:38 - 2009-07-26 21:06 - 01620684 _____ () C:\windows\system32\PerfStringBackup.INI
2015-01-09 14:04 - 2009-12-05 00:51 - 00000000 ___HD () C:\Program Files\Temp
2015-01-09 14:01 - 2014-07-07 08:55 - 00000000 ____D () C:\Users\nightflight\AppData\Local\Adobe
2015-01-05 15:15 - 2014-11-24 17:28 - 00000951 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2015-01-05 15:14 - 2013-08-19 00:18 - 00000000 ___HD () C:\$AVG
==================== Files in the root of some directories =======
2013-09-17 20:51 - 2014-06-23 09:14 - 0003728 _____ () C:\Program Files\Mozilla Firefoxavg-secure-search.xml
2010-08-12 18:50 - 2010-08-13 12:39 - 0001501 _____ () C:\Users\nightflight\AppData\Local\RecConfig.xml
2009-12-05 01:03 - 2009-12-05 01:03 - 0000109 _____ () C:\ProgramData\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}.log
2009-12-05 01:01 - 2009-12-05 01:02 - 0000106 _____ () C:\ProgramData\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}.log
2009-12-05 00:57 - 2009-12-05 00:58 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2009-12-05 01:02 - 2009-12-05 01:03 - 0000110 _____ () C:\ProgramData\{B7A0CE06-068E-11D6-97FD-0050BACBF861}.log
2009-12-05 00:57 - 2009-12-05 00:57 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2009-12-05 00:58 - 2009-12-05 01:01 - 0000110 _____ () C:\ProgramData\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}.log
Some content of TEMP:
====================
C:\Users\nightflight\AppData\Local\temp\Quarantine.exe
C:\Users\nightflight\AppData\Local\temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\explorer.exe => File is digitally signed
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-24 17:31
==================== End Of Log ============================ --- --- ---
--- --- ---
:daumenhoc |