Hi Schrauber,
hier die Logs..
Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Scan Date: 05.02.2015
Scan Time: 19:41:10
Logfile: MBWARE.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.05.08
Rootkit Database: v2015.02.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Frank
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 345075
Time Elapsed: 8 min, 20 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 4
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-4086183471-398018384-2229503660-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Delete-on-Reboot, [726aa872fb8fec4a3fc93fc037cbbc44],
PUP.Optional.SearchProtect.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Quarantined, [726aa872fb8fec4a3fc93fc037cbbc44],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{8a4d5a43-c64a-45ab-bdf4-804fe18ceafd}, Quarantined, [32aa25f5f199db5beabc26e0c4418878],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, Quarantined, [c418b664e1a9da5cb5f01aece42143bd],
Registry Values: 0
(No malicious items detected)
Registry Data: 1
PUP.Optional.Trovi.A, HKU\S-1-5-21-4086183471-398018384-2229503660-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, Suche, Good: (Google), Bad: (Suche,[f3e93edcf19963d31b75e5c3b253956b]
Folders: 6
PUP.Optional.OpenCandy, D:\Users\Frank\AppData\Roaming\OpenCandy, Quarantined, [00dc46d4266411253728df6dbd465ea2],
PUP.Optional.OpenCandy, D:\Users\Frank\AppData\Roaming\OpenCandy\7F2F1E08E20C4103A494DCB7C9F7451A, Quarantined, [00dc46d4266411253728df6dbd465ea2],
PUP.Optional.OpenCandy, D:\Users\Frank\AppData\Roaming\OpenCandy\B4A748549A304B6294A38975124F9D43, Quarantined, [00dc46d4266411253728df6dbd465ea2],
PUP.Optional.OpenCandy, D:\Users\Frank\AppData\Roaming\OpenCandy\OpenCandy_2B679232EA954A7191DA3D76424EBFCE, Quarantined, [00dc46d4266411253728df6dbd465ea2],
PUP.Optional.IHlpr.A, D:\Users\Frank\AppData\Roaming\IHlpr\7F2F1E08E20C4103A494DCB7C9F7451A, Quarantined, [0dcf9288bfcb2b0b0566106da65dd828],
PUP.Optional.IHlpr.A, D:\Users\Frank\AppData\Roaming\IHlpr\B4A748549A304B6294A38975124F9D43, Quarantined, [ecf0ba60fe8c2b0b26459ce133d05fa1],
Files: 2
PUP.Optional.SearchProtect, D:\Windows\AppPatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, Quarantined, [5a82f02a35555fd7c1e8d72fcc397888],
PUP.Optional.IHlpr.A, D:\Users\Frank\AppData\Roaming\IHlpr\7F2F1E08E20C4103A494DCB7C9F7451A\OptimizerPro.exe, Quarantined, [0dcf9288bfcb2b0b0566106da65dd828],
Physical Sectors: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v4.109 - Bericht erstellt am 05/02/2015 um 20:33:27
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-02-04.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Frank - FRANK-PC
# Gestartet von : D:\Users\Frank\Downloads\AdwCleaner_4.109.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gefunden : D:\Users\Frank\AppData\Local\DownloadManager
Ordner Gefunden : D:\Users\Frank\AppData\Roaming\IHlpr
Ordner Gefunden : D:\Users\Frank\AppData\Roaming\RHEng
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKCU\Software\OCS
Schlüssel Gefunden : HKCU\Software\Optimizer Pro
Schlüssel Gefunden : [x64] HKCU\Software\OCS
Schlüssel Gefunden : [x64] HKCU\Software\Optimizer Pro
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gefunden : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v35.0.1 (x86 de)
*************************
AdwCleaner[R0].txt - [1974 octets] - [05/02/2015 20:02:19]
AdwCleaner[R1].txt - [1878 octets] - [05/02/2015 20:33:27]
########## EOF - D:\AdwCleaner\AdwCleaner[R1].txt - [1938 octets] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Frank on 05.02.2015 at 20:50:48,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "D:\Users\Frank\appdata\local\downloadmanager"
~~~ FireFox
Emptied folder: D:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\ojwzzcxm.default\minidumps [17 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.02.2015 at 20:53:52,76
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2015
Ran by Frank (administrator) on FRANK-PC on 05-02-2015 20:54:31
Running from D:\Users\Frank\Desktop
Loaded Profiles: Frank (Available profiles: Frank)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) D:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) D:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Creative Technology Ltd) D:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) D:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Samsung) D:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(Samsung) D:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(CHENGDU YIWO Tech Development Co., Ltd) D:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) D:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Copyright 2013 SAMSUNG) D:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) D:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Microsoft Corp.) D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
() D:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
(Microsoft Corp.) D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) D:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) D:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) D:\Windows\System32\vds.exe
(Copyright 2013 SAMSUNG) D:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(Creative Technology Ltd) D:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() D:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe
(Avira Operations GmbH & Co. KG) D:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Oracle Corporation) D:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(eMule-Project.net - Official eMule Homepage. Downloads, Help, Docu, News...) D:\Program Files (x86)\eMule\emule.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => D:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585928 2015-01-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => D:\Windows\system32\rundll32.exe D:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Samsung Link] => D:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2014-12-16] (Copyright 2013 SAMSUNG)
HKLM-x32\...\Run: [UpdReg] => D:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [Sound Blaster Recon3D PCIe Control Panel] => D:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe [976896 2012-12-18] (Creative Technology Ltd)
HKLM-x32\...\Run: [avgnt] => D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => D:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [AgentMonitor] => D:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [401280 2014-06-20] ()
HKLM-x32\...\Run: [Avira Systray] => D:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-4086183471-398018384-2229503660-1000\...\Run: [BitTorrent] => D:\Users\Frank\AppData\Roaming\BitTorrent\BitTorrent.exe [1376600 2015-01-21] (BitTorrent Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-4086183471-398018384-2229503660-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-4086183471-398018384-2229503660-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4086183471-398018384-2229503660-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-21-4086183471-398018384-2229503660-1000 -> DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> D:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> D:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> D:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> D:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> D:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> D:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> D:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - D:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: D:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ojwzzcxm.default
FF Plugin: @adobe.com/FlashPlayer -> D:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> D:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> D:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> D:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> D:\PROGRA~1\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> D:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @canon.com/EPPEX -> D:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> D:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> D:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> D:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> D:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> D:\PROGRA~2\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> D:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> D:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader -> D:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: D:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Extension: Avira Browser Safety - D:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ojwzzcxm.default\Extensions\abs@avira.com [2015-02-02]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - D:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\ojwzzcxm.default\Extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900} [2014-12-27]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - D:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2015-01-26]
FF HKU\S-1-5-21-4086183471-398018384-2229503660-1000\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - D:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - D:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-12-27]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AllShare Framework DMS; D:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
R2 AntiVirSchedulerService; D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; D:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [178424 2014-12-31] (Avira Operations GmbH & Co. KG)
R2 CTAudSvcService; D:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2012-10-08] (Creative Technology Ltd) [File not signed]
S2 CtHdaSvc; D:\Windows\sysWow64\CtHdaSvc.exe [103936 2013-07-30] (Creative Technology Ltd)
R2 EaseUS Agent; D:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [37384 2014-10-14] (CHENGDU YIWO Tech Development Co., Ltd)
R2 GfExperienceService; D:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148744 2015-01-16] (NVIDIA Corporation)
S2 MBAMScheduler; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NvNetworkService; D:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706312 2015-01-16] (NVIDIA Corporation)
R2 NvStreamSvc; D:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833544 2015-01-16] (NVIDIA Corporation)
R2 Samsung Link Service; D:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2014-12-16] (Copyright 2013 SAMSUNG)
R2 WinDefend; D:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; D:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; D:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-23] (Avira Operations GmbH & Co. KG)
R1 avipbb; D:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-23] (Avira Operations GmbH & Co. KG)
R1 avkmgr; D:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-10-23] (Avira Operations GmbH & Co. KG)
S3 cthda; D:\Windows\System32\drivers\cthda.sys [1049880 2013-07-30] (Creative Technology Ltd)
R3 cthdb; D:\Windows\System32\DRIVERS\cthdb.sys [28440 2013-07-30] (Creative Technology Ltd)
S3 epmntdrv; D:\Windows\system32\epmntdrv.sys [18528 2014-11-18] ()
S3 epmntdrv; D:\Windows\SysWOW64\epmntdrv.sys [14944 2014-11-18] ()
R0 EUBKMON; D:\Windows\System32\drivers\EUBKMON.sys [48136 2014-10-14] ()
S3 EuGdiDrv; D:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] ()
S3 EuGdiDrv; D:\Windows\SysWOW64\EuGdiDrv.sys [10208 2014-11-18] ()
S3 MBAMProtector; D:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; D:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 NvStreamKms; D:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19784 2015-01-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; D:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 catchme; \??\D:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-05 20:54 - 2015-02-05 20:54 - 00016266 _____ () D:\Users\Frank\Desktop\FRST.txt
2015-02-05 20:54 - 2015-02-05 20:54 - 00000000 ____D () D:\Users\Frank\Desktop\FRST-OlderVersion
2015-02-05 20:53 - 2015-02-05 20:53 - 00000838 _____ () D:\Users\Frank\Desktop\JRT.txt
2015-02-05 20:51 - 2015-02-05 20:51 - 00002034 _____ () D:\Users\Frank\Desktop\AdwCleaner[R1].txt
2015-02-05 20:50 - 2015-02-05 20:50 - 01388274 _____ (Thisisu) D:\Users\Frank\Downloads\JRT.exe
2015-02-05 20:01 - 2015-02-05 20:34 - 00000000 ____D () D:\AdwCleaner
2015-02-05 20:01 - 2015-02-05 20:01 - 02194432 _____ () D:\Users\Frank\Downloads\AdwCleaner_4.109.exe
2015-02-05 19:59 - 2015-02-05 19:59 - 00003568 _____ () D:\Users\Frank\Desktop\MBWARE.txt
2015-02-05 19:40 - 2015-02-05 19:53 - 00129752 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-05 19:40 - 2015-02-05 19:40 - 00001102 _____ () D:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-05 19:40 - 2015-02-05 19:40 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-05 19:40 - 2015-02-05 19:40 - 00000000 ____D () D:\ProgramData\Malwarebytes
2015-02-05 19:40 - 2015-02-05 19:40 - 00000000 ____D () D:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-05 19:40 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-05 19:40 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\mwac.sys
2015-02-05 19:40 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) D:\Windows\system32\Drivers\mbam.sys
2015-02-05 19:39 - 2015-02-05 19:39 - 20447072 _____ (Malwarebytes Corporation ) D:\Users\Frank\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-03 19:42 - 2015-02-03 19:42 - 00030738 _____ () D:\ComboFix.txt
2015-02-03 19:30 - 2011-06-26 07:45 - 00256000 _____ () D:\Windows\PEV.exe
2015-02-03 19:30 - 2010-11-07 18:20 - 00208896 _____ () D:\Windows\MBR.exe
2015-02-03 19:30 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) D:\Windows\NIRCMD.exe
2015-02-03 19:30 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) D:\Windows\SWREG.exe
2015-02-03 19:30 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) D:\Windows\SWSC.exe
2015-02-03 19:30 - 2000-08-31 01:00 - 00098816 _____ () D:\Windows\sed.exe
2015-02-03 19:30 - 2000-08-31 01:00 - 00080412 _____ () D:\Windows\grep.exe
2015-02-03 19:30 - 2000-08-31 01:00 - 00068096 _____ () D:\Windows\zip.exe
2015-02-03 19:29 - 2015-02-03 19:42 - 00000000 ____D () D:\Qoobox
2015-02-03 19:29 - 2015-02-03 19:41 - 00000000 ____D () D:\Windows\erdnt
2015-02-03 19:28 - 2015-02-03 19:28 - 05611380 ____R (Swearware) D:\Users\Frank\Downloads\ComboFix.exe
2015-02-03 19:25 - 2015-02-03 19:25 - 02623656 _____ (VS Revo Group Ltd.) D:\Users\Frank\Downloads\revosetup95.exe
2015-02-03 19:25 - 2015-02-03 19:25 - 00000000 ____D () D:\Program Files (x86)\VS Revo Group
2015-02-02 19:57 - 2015-02-05 20:54 - 02131968 _____ (Farbar) D:\Users\Frank\Desktop\FRST64.exe
2015-02-02 19:57 - 2015-02-05 20:54 - 00000000 ____D () D:\FRST
2015-02-02 19:24 - 2015-02-02 19:25 - 00000173 _____ () D:\Users\Frank\Desktop\fixexe.reg
2015-01-29 21:54 - 2015-02-03 00:03 - 00000000 ____D () D:\Users\Frank\AppData\Local\PokerStars.BE
2015-01-29 21:54 - 2015-01-29 21:54 - 00001982 _____ () D:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.be.lnk
2015-01-29 21:54 - 2015-01-29 21:54 - 00001976 _____ () D:\Users\Public\Desktop\PokerStars.be.lnk
2015-01-29 21:54 - 2015-01-29 21:54 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.BE
2015-01-29 21:53 - 2015-01-29 21:54 - 00000000 ____D () D:\Program Files (x86)\PokerStars.BE
2015-01-29 21:50 - 2015-01-29 21:51 - 59305984 _____ (PokerStars) D:\Users\Frank\Downloads\PokerStarsInstallBE.exe
2015-01-27 14:20 - 2015-01-27 14:25 - 00000000 ____D () D:\Users\Frank\Documents\Fax
2015-01-26 20:20 - 2015-01-12 23:13 - 00000000 ____D () D:\Users\Frank\Desktop\Elvis_Presley-Elvis.80-2014-NoGroup
2015-01-26 20:20 - 2014-12-18 10:27 - 1583536076 _____ () D:\Users\Frank\Desktop\xf-wackenrep.mkv
2015-01-26 20:18 - 2015-01-26 20:18 - 00000000 ____D () D:\Users\Frank\Desktop\From.Dusk.Till.Dawn.Extendend
2015-01-26 20:09 - 2015-01-17 14:18 - 630191031 _____ () D:\Users\Frank\Desktop\pso-the.drop-bd_sd.mkv
2015-01-26 20:09 - 2015-01-09 23:27 - 00621200 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvStreaming.exe
2015-01-26 20:08 - 2015-01-26 20:08 - 00000000 ____D () D:\Users\Frank\Desktop\Dracula.untold
2015-01-26 20:07 - 2015-01-17 14:18 - 00535552 _____ () D:\Users\Frank\Desktop\remove_this
2015-01-26 20:07 - 2015-01-13 05:15 - 01540240 _____ (NVIDIA Corporation) D:\Windows\system32\nvhdagenco6420103.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 32102544 _____ (NVIDIA Corporation) D:\Windows\system32\nvoglv64.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 25459856 _____ (NVIDIA Corporation) D:\Windows\system32\nvcompiler.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 24765584 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvoglv32.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 20465296 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvcompiler.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 13295552 _____ (NVIDIA Corporation) D:\Windows\system32\nvopencl.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 13210248 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuda.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 10774544 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvopencl.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 10714488 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvcuda.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 10274448 _____ (NVIDIA Corporation) D:\Windows\system32\Drivers\nvlddmkm.sys
2015-01-26 20:07 - 2015-01-10 09:07 - 03607184 _____ (NVIDIA Corporation) D:\Windows\system32\nvcuvid.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 03245712 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvcuvid.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 02902456 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvapi.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 01895240 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispco6434725.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 01556808 _____ (NVIDIA Corporation) D:\Windows\system32\nvdispgenco6434725.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00994712 _____ (NVIDIA Corporation) D:\Windows\system32\nvumdshimx.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00969360 _____ (NVIDIA Corporation) D:\Windows\system32\NvIFR64.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00942736 _____ (NVIDIA Corporation) D:\Windows\system32\NvFBC64.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00929424 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\NvIFR.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00906384 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\NvFBC.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00877488 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvumdshim.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00496456 _____ (NVIDIA Corporation) D:\Windows\system32\nvEncodeAPI64.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00399688 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvEncodeAPI.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00390472 _____ (NVIDIA Corporation) D:\Windows\system32\NvIFROpenGL.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00353040 _____ (NVIDIA Corporation) D:\Windows\system32\nvoglshim64.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00345744 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\NvIFROpenGL.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00305320 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvoglshim32.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00177624 _____ (NVIDIA Corporation) D:\Windows\system32\nvinitx.dll
2015-01-26 20:07 - 2015-01-10 09:07 - 00164568 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvinit.dll
2015-01-26 19:55 - 2015-01-03 17:43 - 00000220 _____ () D:\Users\Frank\Desktop\Goldesel.to - Die Seite fuer Direkt-Downloads aller Art.url
2015-01-26 19:48 - 2015-02-05 15:28 - 00000000 ____D () D:\Program Files (x86)\Mozilla Firefox
2015-01-24 16:11 - 2015-01-21 23:43 - 796177410 _____ () D:\Users\Frank\Desktop\roor-cooper-sd.mkv
2015-01-20 21:53 - 2015-01-20 21:53 - 00004590 _____ () D:\Users\Frank\AppData\Local\recently-used.xbel
2015-01-20 20:58 - 2015-01-20 21:53 - 00000000 ____D () D:\Users\Frank\AppData\Local\gtk-2.0
2015-01-20 20:58 - 2015-01-20 20:58 - 00000000 ____D () D:\Users\Frank\.thumbnails
2015-01-20 20:56 - 2015-02-02 19:29 - 00000000 ____D () D:\Users\Frank\.gimp-2.8
2015-01-20 20:56 - 2015-01-20 20:56 - 00000000 ____D () D:\Users\Frank\AppData\Local\gegl-0.2
2015-01-20 20:55 - 2015-01-20 20:55 - 00000894 _____ () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2015-01-20 20:54 - 2015-01-20 20:55 - 00000000 ____D () D:\Program Files\GIMP 2
2015-01-20 20:49 - 2015-01-20 20:53 - 91670064 _____ (The GIMP Team ) D:\Users\Frank\Downloads\gimp-2.8.14-setup.exe
2015-01-19 19:21 - 2015-01-19 19:26 - 00000000 ____D () D:\Users\Frank\AppData\OICE_15_974FA576_32C1D314_14AD
2015-01-19 19:13 - 2015-02-05 20:15 - 00004956 _____ () D:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Frank-PC-Frank Frank-PC
2015-01-19 19:13 - 2015-01-19 19:20 - 00000000 ____D () D:\Users\Frank\AppData\OICE_15_974FA576_32C1D314_1F65
2015-01-16 08:43 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) D:\Windows\system32\nlasvc.dll
2015-01-16 08:43 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ncsi.dll
2015-01-16 08:43 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) D:\Windows\SysWOW64\nlaapi.dll
2015-01-15 09:06 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) D:\Windows\system32\profsvc.dll
2015-01-15 09:06 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) D:\Windows\system32\Drivers\mrxdav.sys
2015-01-15 09:06 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) D:\Windows\system32\ntoskrnl.exe
2015-01-15 09:06 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) D:\Windows\system32\srcore.dll
2015-01-15 09:06 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) D:\Windows\system32\rstrui.exe
2015-01-15 09:06 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) D:\Windows\system32\srclient.dll
2015-01-15 09:06 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-15 09:06 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) D:\Windows\SysWOW64\ntoskrnl.exe
2015-01-15 09:06 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) D:\Windows\SysWOW64\srclient.dll
2015-01-15 09:06 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) D:\Windows\system32\TSWbPrxy.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-05 20:54 - 2014-12-07 09:34 - 00000000 ____D () D:\TEMP
2015-02-05 20:35 - 2014-12-11 21:54 - 00000884 _____ () D:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-05 20:00 - 2009-07-14 05:45 - 00013760 ____H () D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-05 20:00 - 2009-07-14 05:45 - 00013760 ____H () D:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-05 19:56 - 2014-12-03 19:32 - 01572637 _____ () D:\Windows\WindowsUpdate.log
2015-02-05 19:55 - 2014-12-05 17:53 - 00000000 ____D () D:\Users\Frank\AppData\Roaming\BitTorrent
2015-02-05 19:51 - 2014-12-05 03:46 - 00248784 _____ () D:\Windows\PFRO.log
2015-02-05 19:51 - 2014-12-03 21:54 - 00000000 ____D () D:\ProgramData\NVIDIA
2015-02-05 19:51 - 2009-07-14 06:08 - 00000006 ____H () D:\Windows\Tasks\SA.DAT
2015-02-05 19:51 - 2009-07-14 05:51 - 00046349 _____ () D:\Windows\setupact.log
2015-02-05 19:50 - 2014-12-05 17:06 - 00000000 ____D () D:\Users\Frank\AppData\Roaming\IHlpr
2015-02-05 01:35 - 2014-12-11 21:54 - 00003822 _____ () D:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-05 01:35 - 2014-12-04 14:25 - 00701616 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 01:35 - 2014-12-04 14:25 - 00071344 _____ (Adobe Systems Incorporated) D:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-03 19:42 - 2009-07-14 04:20 - 00000000 __RHD () D:\Users\Default
2015-02-03 19:38 - 2009-07-14 03:34 - 00000215 _____ () D:\Windows\system.ini
2015-02-02 20:19 - 2009-07-14 06:32 - 00000000 ____D () D:\Windows\system32\FxsTmp
2015-02-02 19:22 - 2009-07-14 18:58 - 00699416 _____ () D:\Windows\system32\perfh007.dat
2015-02-02 19:22 - 2009-07-14 18:58 - 00149556 _____ () D:\Windows\system32\perfc007.dat
2015-02-02 19:22 - 2009-07-14 06:13 - 01620612 _____ () D:\Windows\system32\PerfStringBackup.INI
2015-02-02 11:15 - 2009-07-14 04:20 - 00000000 ____D () D:\Windows\system32\NDF
2015-01-31 21:00 - 2014-12-07 19:38 - 00000000 ____D () D:\Users\Frank\AppData\Roaming\vlc
2015-01-29 16:00 - 2014-12-03 22:10 - 00000000 ____D () D:\ProgramData\Package Cache
2015-01-29 16:00 - 2014-12-03 22:10 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-01-29 16:00 - 2014-12-03 22:10 - 00000000 ____D () D:\Program Files (x86)\Avira
2015-01-27 01:11 - 2014-12-03 21:12 - 00000000 ____D () D:\Program Files (x86)\Mozilla Maintenance Service
2015-01-26 20:09 - 2014-12-03 22:02 - 00000000 ____D () D:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-01-20 20:58 - 2014-12-03 20:11 - 00000000 ____D () D:\Users\Frank
2015-01-16 07:41 - 2014-12-03 22:03 - 01756424 _____ (NVIDIA Corporation) D:\Windows\system32\nvspbridge64.dll
2015-01-16 07:41 - 2014-12-03 22:03 - 01514528 _____ (NVIDIA Corporation) D:\Windows\system32\nvspcap64.dll
2015-01-16 07:41 - 2014-12-03 22:03 - 01316184 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvspbridge.dll
2015-01-16 07:41 - 2014-12-03 22:03 - 01278920 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvspcap.dll
2015-01-15 22:37 - 2014-12-05 17:56 - 00000000 ____D () D:\Users\Frank\AppData\Roaming\Skype
2015-01-15 22:20 - 2014-12-05 17:56 - 00000000 ___RD () D:\Program Files (x86)\Skype
2015-01-15 22:20 - 2014-12-05 17:55 - 00000000 ____D () D:\ProgramData\Skype
2015-01-15 12:57 - 2014-12-05 16:45 - 00000000 ____D () D:\Windows\system32\MRT
2015-01-15 12:54 - 2014-12-05 16:45 - 113365784 _____ (Microsoft Corporation) D:\Windows\system32\MRT.exe
2015-01-10 09:07 - 2014-12-24 05:56 - 17250776 _____ (NVIDIA Corporation) D:\Windows\system32\nvd3dumx.dll
2015-01-10 09:07 - 2014-12-24 05:56 - 16009120 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvwgf2um.dll
2015-01-10 09:07 - 2014-12-03 21:53 - 18566296 _____ (NVIDIA Corporation) D:\Windows\system32\nvwgf2umx.dll
2015-01-10 09:07 - 2014-12-03 21:53 - 14115944 _____ (NVIDIA Corporation) D:\Windows\SysWOW64\nvd3dum.dll
2015-01-10 09:07 - 2014-12-03 21:53 - 03298816 _____ (NVIDIA Corporation) D:\Windows\system32\nvapi64.dll
2015-01-10 09:07 - 2014-12-03 21:53 - 00073872 _____ (Khronos Group) D:\Windows\system32\OpenCL.dll
2015-01-10 09:07 - 2014-12-03 21:53 - 00060744 _____ (Khronos Group) D:\Windows\SysWOW64\OpenCL.dll
2015-01-10 09:07 - 2014-12-03 21:53 - 00027441 _____ () D:\Windows\system32\nvinfo.pb
2015-01-10 00:30 - 2014-12-03 21:53 - 06860432 _____ (NVIDIA Corporation) D:\Windows\system32\nvcpl.dll
2015-01-10 00:30 - 2014-12-03 21:53 - 03517256 _____ (NVIDIA Corporation) D:\Windows\system32\nvsvc64.dll
2015-01-10 00:29 - 2014-12-03 21:53 - 02558608 _____ (NVIDIA Corporation) D:\Windows\system32\nvsvcr.dll
2015-01-10 00:29 - 2014-12-03 21:53 - 00935056 _____ (NVIDIA Corporation) D:\Windows\system32\nvvsvc.exe
2015-01-10 00:29 - 2014-12-03 21:53 - 00385352 _____ (NVIDIA Corporation) D:\Windows\system32\nvmctray.dll
2015-01-10 00:29 - 2014-12-03 21:53 - 00062608 _____ (NVIDIA Corporation) D:\Windows\system32\nvshext.dll
2015-01-09 20:47 - 2014-12-03 21:53 - 04173527 _____ () D:\Windows\system32\nvcoproc.bin
2015-01-09 15:54 - 2014-12-26 13:37 - 00000000 ____D () D:\Users\Frank\Downloads\www.fusion-torrent.to_F.E.A.R_2_-_Project_Origin.READNFO-TL.FtR
2015-01-06 16:42 - 2014-12-03 21:12 - 00000000 ____D () D:\Users\Frank\AppData\Local\Windows Live
2015-01-06 04:36 - 2014-12-03 21:20 - 00298120 ____N (Microsoft Corporation) D:\Windows\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2015-01-20 21:53 - 2015-01-20 21:53 - 0004590 _____ () D:\Users\Frank\AppData\Local\recently-used.xbel
Some content of TEMP:
====================
D:\Users\Frank\AppData\Local\Temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
D:\Windows\System32\winlogon.exe => File is digitally signed
D:\Windows\System32\wininit.exe => File is digitally signed
D:\Windows\SysWOW64\wininit.exe => File is digitally signed
D:\Windows\explorer.exe => File is digitally signed
D:\Windows\SysWOW64\explorer.exe => File is digitally signed
D:\Windows\System32\svchost.exe => File is digitally signed
D:\Windows\SysWOW64\svchost.exe => File is digitally signed
D:\Windows\System32\services.exe => File is digitally signed
D:\Windows\System32\User32.dll => File is digitally signed
D:\Windows\SysWOW64\User32.dll => File is digitally signed
D:\Windows\System32\userinit.exe => File is digitally signed
D:\Windows\SysWOW64\userinit.exe => File is digitally signed
D:\Windows\System32\rpcss.dll => File is digitally signed
D:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-03 11:09
==================== End Of Log ============================
--- --- ---