So, hier die Dateien. Übrigens: TOP - Hilfestellung, die Du gibst. Das kann selbst ein Laie wie ich leicht abarbeiten! Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 05.02.2015
Scan Time: 10:46:13
Logfile: malwareb.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2015.02.05.04
Rootkit Database: v2015.02.03.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Tyrion Lannister
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 349405
Time Elapsed: 15 min, 26 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 24
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\FlashBeat, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{1B0071C9-831E-43DD-9EFE-722D8AEB9E2E}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{5217E897-1728-4B11-BC9D-5405AD551BEF}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6073385E-A128-4464-9DFD-C7CF0F39A492}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{81E47395-D310-4064-B963-844C4088AB76}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{83E41C3D-190A-4052-A046-269722F3B4FD}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A62D52D9-1E41-4772-A794-71B9B92AA014}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{D1C116A0-DC17-4257-9190-033AE10F90B9}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{ED5B55CA-994B-42B9-93B6-1FD306925967}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FB7F9DF6-2A66-444F-BA5D-2F221F1B1AC8}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{B8D1E62C-5D04-4AB0-A09E-688FF75743EF}, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.MediaPlayer.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\video MediaPlay-Air, Delete-on-Reboot, [5e7a1bffacde0d29e7fd03fe60a56f91],
PUP.Optional.WebInternetSecurity, HKU\S-1-5-21-1453844191-4196955726-2398730128-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\webinternetsecurity, Delete-on-Reboot, [37a14bcf7d0d1b1b6330e2bdbc477888],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1453844191-4196955726-2398730128-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WIntEnhance, Delete-on-Reboot, [e7f1ca500387dd5952cfc6be788b4db3],
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 1
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
Files: 27
PUP.Optional.Spigot, C:\Users\Tyrion Lannister\Downloads\YTDSetup481.exe, Quarantined, [b7218397177356e0a25f04bd8d744bb5],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\uninstall.exe, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\ColorMedia.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\ColorMedia.exe, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\ColorMedia.tlb, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\ColorMedia64.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\ColorMediaCrt.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\freebl3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\libnspr4.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\libplc4.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\libplds4.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\nss3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\nssckbi.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\nssdbm3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\nssutil3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\RfndNSIS.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\RgsBTMedia.exe, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\RgsBTMedia.ini, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\RgsBTMedia64.exe, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\smime3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\softokn3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\sqlite3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.FlashBeat.A, C:\ProgramData\FlashBeat\ssl3.dll, Quarantined, [e4f4c357c4c6ae88455010731fe4d828],
PUP.Optional.WebsSearches.A, C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Local Storage\http_istart.webssearches.com_0.localstorage, Delete-on-Reboot, [459381992664d1657fd5137202019b65],
PUP.Optional.WebsSearches.A, C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Local Storage\http_istart.webssearches.com_0.localstorage-journal, Delete-on-Reboot, [45938b8f068455e165efff86e61d2cd4],
PUP.Optional.ColorMedia.A, C:\Windows\SysWOW64\ColorMedia.ini, Quarantined, [d800e337444678be1efbaf584abbac54],
PUP.Optional.ColorMedia.A, C:\Windows\System32\ColorMediaOff.ini, Quarantined, [0aceea304e3c40f650ca0205ee17f20e],
Physical Sectors: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v4.109 - Bericht erstellt am 05/02/2015 um 11:19:51
# Aktualisiert 24/01/2015 von Xplode
# Database : 2015-02-04.1 [Live]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Tyrion Lannister - ARBEITSZIMMER
# Gestartet von : C:\Users\Tyrion Lannister\Desktop\AdwCleaner_4.109.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_istart.webssearches.com_0.localstorage
Datei Gelöscht : C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_istart.webssearches.com_0.localstorage-journal
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Mozilla Firefox v32.0.3 (x86 de)
-\\ Google Chrome v40.0.2214.94
[C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1422700771&from=cvs5&uid=395049983_1052499_A086D6BD&q={searchTerms}
[C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1422700771&from=cvs5&uid=395049983_1052499_A086D6BD&q={searchTerms}
[C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1422700771&from=cvs5&uid=395049983_1052499_A086D6BD&q={searchTerms}
[C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Gelöscht [Search Provider] : hxxp://istart.webssearches.com/web/?type=ds&ts=1422700771&from=cvs5&uid=395049983_1052499_A086D6BD&q={searchTerms}
*************************
AdwCleaner[R0].txt - [12974 octets] - [04/02/2015 10:21:21]
AdwCleaner[R1].txt - [2191 octets] - [05/02/2015 11:18:29]
AdwCleaner[S0].txt - [11998 octets] - [04/02/2015 10:28:02]
AdwCleaner[S1].txt - [2112 octets] - [05/02/2015 11:19:51]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2172 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by Tyrion Lannister on 05.02.2015 at 11:26:41,53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\Tyrion Lannister\appdata\local\google\chrome\user data\default\local storage\http_istart.webssearches.com_0.localstorage"
Successfully deleted: [File] "C:\Users\Tyrion Lannister\appdata\local\google\chrome\user data\default\local storage\http_istart.webssearches.com_0.localstorage-journal"
Successfully deleted: [File] C:\Windows\prefetch\DRIVERGENIUS.EXE-386264C9.pf
~~~ Folders
~~~ FireFox
Successfully deleted: [File] C:\Users\Tyrion Lannister\AppData\Roaming\mozilla\firefox\profiles\j1wx7dxm.default\searchplugins\avira-safesearch.xml
Successfully deleted: [Folder] C:\Users\Tyrion Lannister\AppData\Roaming\mozilla\firefox\profiles\j1wx7dxm.default\extensions\safesearch@avira.com
Successfully deleted the following from C:\Users\Tyrion Lannister\AppData\Roaming\mozilla\firefox\profiles\j1wx7dxm.default\prefs.js
user_pref("avira.safe_search.search_was_active", "false");
user_pref("extensions.bootstrappedAddons", "{\"jid1-P34HaABBBpOerQ@jetpack\":{\"version\":\"0.2\",\"type\":\"extension\",\"descriptor\":\"C:\\\\Users\\\\Tyrion Lannister\\\\Ap
Emptied folder: C:\Users\Tyrion Lannister\AppData\Roaming\mozilla\firefox\profiles\j1wx7dxm.default\minidumps [1 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.02.2015 at 11:31:06,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2015 01
Ran by Tyrion Lannister (administrator) on ARBEITSZIMMER on 05-02-2015 11:33:52
Running from C:\Users\Tyrion Lannister\Desktop\Viren
Loaded Profiles: Tyrion Lannister (Available profiles: Tyrion Lannister)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
() C:\Users\Tyrion Lannister\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesApp64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Arc] => C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcLauncher.exe [416080 2015-01-08] (Perfect World Entertainment)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [448856 2014-08-19] (DivX, LLC)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1453844191-4196955726-2398730128-1000\...\Run: [Amazon Music] => C:\Users\Tyrion Lannister\AppData\Local\Amazon Music\Amazon Music Helper.exe [6277952 2014-12-08] ()
BootExecute: autocheck autochk * ????????? ????????
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1453844191-4196955726-2398730128-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1453844191-4196955726-2398730128-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @gametap.com/npdd,version=1.0 -> C:\Program Files (x86)\Downloader\npdd.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.9.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.9.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1453844191-4196955726-2398730128-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\searchplugins\google-images.xml
FF SearchPlugin: C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\searchplugins\google-maps.xml
FF Extension: Avira Browser Safety - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\abs@avira.com [2014-11-21]
FF Extension: DownloadHelper - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-09-05]
FF Extension: Cliqz Beta - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\cliqz@cliqz.com.xpi [2014-09-18]
FF Extension: Ghostery - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\firefox@ghostery.com.xpi [2014-07-07]
FF Extension: Strict Pop-up Blocker - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\jid1-P34HaABBBpOerQ@jetpack.xpi [2014-07-07]
FF Extension: NoScript - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-07-07]
FF Extension: Adblock Plus - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-07-07]
FF Extension: DownThemAll! - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2014-07-07]
FF HKU\S-1-5-21-1453844191-4196955726-2398730128-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\extensions\cliqz@cliqz.com
FF Extension: No Name - C:\Users\Tyrion Lannister\AppData\Roaming\Mozilla\Firefox\Profiles\j1wx7dxm.default\extensions\faststartff@gmail.com [Not Found]
Chrome:
=======
CHR HomePage: Default -> hxxp://istart.webssearches.com/?type=hp&ts=1422700771&from=cvs5&uid=395049983_1052499_A086D6BD
CHR StartupUrls: Default -> "hxxp://istart.webssearches.com/?type=hp&ts=1422700771&from=cvs5&uid=395049983_1052499_A086D6BD"
CHR DefaultSearchKeyword: Default -> webssearches
CHR DefaultSuggestURL: Default ->
CHR Profile: C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default
CHR Extension: (Google Slides) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-09-17]
CHR Extension: (Google Docs) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-09-17]
CHR Extension: (Google Drive) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-09-17]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-18]
CHR Extension: (YouTube) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-09-17]
CHR Extension: (Google Search) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-09-17]
CHR Extension: (Google Sheets) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-09-17]
CHR Extension: (Avira Browser Safety) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-02-05]
CHR Extension: (Google Wallet) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-17]
CHR Extension: (Gmail) - C:\Users\Tyrion Lannister\AppData\Local\Google\Chrome\User Data\default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-09-17]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2011-11-09] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-04] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [992560 2014-12-04] (Avira Operations GmbH & Co. KG)
S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2015-01-08] (Perfect World Entertainment Inc)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [178424 2014-12-31] (Avira Operations GmbH & Co. KG)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] ()
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-01-10] (SurfRight B.V.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-03] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 MSSQL$BWDATOOLSET; C:\Program Files (x86)\DAODB\MSSQL.1\MSSQL\Binn\sqlservr.exe [29263712 2008-11-25] (Microsoft Corporation)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesService64.exe [2145080 2014-07-16] (TuneUp Software)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 WTGService; C:\Program Files (x86)\Verbindungsassistent\WTGService.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-14] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
S3 Huawei; C:\Windows\System32\DRIVERS\ewdcsc.sys [29696 2014-11-09] (Huawei Tech. Co., Ltd.)
S3 Huawei; C:\Windows\SysWOW64\DRIVERS\ewdcsc.sys [29696 2014-11-09] (Huawei Tech. Co., Ltd.)
S3 hwdatacard; C:\Windows\SysWOW64\DRIVERS\ewusbmdm.sys [115328 2008-07-24] (Huawei Technologies Co., Ltd.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-05] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2014\TuneUpUtilitiesDriver64.sys [14112 2013-08-21] (TuneUp Software)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-05 11:31 - 2015-02-05 11:31 - 00001861 _____ () C:\Users\Tyrion Lannister\Desktop\JRT.txt
2015-02-05 11:25 - 2015-02-05 11:25 - 01388274 _____ (Thisisu) C:\Users\Tyrion Lannister\Desktop\JRT.exe
2015-02-05 11:22 - 2015-02-05 11:22 - 00002252 _____ () C:\Users\Tyrion Lannister\Desktop\AdwCleaner[S1].txt
2015-02-05 11:16 - 2015-02-05 11:16 - 00008522 _____ () C:\Users\Tyrion Lannister\Desktop\mbam.txt
2015-02-05 11:02 - 2015-02-05 11:02 - 00008284 _____ () C:\Users\Tyrion Lannister\Desktop\malwareb.txt
2015-02-05 10:45 - 2015-02-05 11:23 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-05 10:45 - 2015-02-05 10:45 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-05 10:45 - 2015-02-05 10:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-05 10:45 - 2015-02-05 10:45 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-05 10:45 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-05 10:45 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-05 10:45 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-05 01:48 - 2015-02-05 01:48 - 00000000 ____D () C:\Users\Tyrion Lannister\Desktop\Colani
2015-02-05 01:05 - 2015-02-05 01:05 - 00038451 _____ () C:\ComboFix.txt
2015-02-05 00:30 - 2015-02-05 00:15 - 05611380 ____R (Swearware) C:\Users\Tyrion Lannister\Desktop\ComboFix.exe
2015-02-05 00:18 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-05 00:18 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-05 00:18 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-05 00:18 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-05 00:18 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-05 00:18 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-05 00:18 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-05 00:18 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-05 00:16 - 2015-02-05 01:05 - 00000000 ____D () C:\Qoobox
2015-02-05 00:16 - 2015-02-05 01:04 - 00000000 ____D () C:\Windows\erdnt
2015-02-05 00:10 - 2015-02-05 00:10 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-04 11:06 - 2015-02-05 11:33 - 00000000 ____D () C:\Users\Tyrion Lannister\Desktop\Viren
2015-02-04 10:35 - 2015-02-05 11:33 - 00000000 ____D () C:\FRST
2015-02-04 10:21 - 2015-02-05 11:19 - 00000000 ____D () C:\AdwCleaner
2015-02-04 10:20 - 2015-02-04 10:20 - 02194432 _____ () C:\Users\Tyrion Lannister\Desktop\AdwCleaner_4.109.exe
2015-02-03 13:03 - 2015-02-03 13:03 - 00001115 _____ () C:\Users\Tyrion Lannister\Desktop\Driver Genius Professional Edition.lnk
2015-02-03 13:03 - 2015-02-03 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius Professional Edition
2015-02-03 01:46 - 2015-02-03 01:46 - 16032147 _____ (Written by Alexander Herzog) C:\Users\Tyrion Lannister\Desktop\D-Fend-Reloaded-1.4.1-Setup.exe
2015-02-01 11:34 - 2015-02-01 11:34 - 00032151 _____ () C:\Users\Tyrion Lannister\Desktop\a_charming_font.zip
2015-02-01 11:34 - 2015-02-01 11:34 - 00000000 ____D () C:\Users\Tyrion Lannister\AppData\Roaming\dlg
2015-01-31 11:40 - 2015-01-31 11:40 - 00000000 ____D () C:\ProgramData\FlashBeatData
2015-01-31 11:40 - 2015-01-27 17:31 - 00344440 _____ (CartCrunch Israel Ltd.) C:\Windows\system32\ColorMedia64.dll
2015-01-31 11:40 - 2015-01-27 17:31 - 00301168 _____ (CartCrunch Israel Ltd.) C:\Windows\SysWOW64\ColorMedia.dll
2015-01-31 11:38 - 2015-01-31 11:38 - 00432280 _____ () C:\Users\Tyrion Lannister\Desktop\ACharmingFont_downloader-Q6Sb7gh66.exe
2015-01-31 11:37 - 2015-01-31 11:37 - 00432280 _____ () C:\Users\Tyrion Lannister\Downloads\ACharmingFont_downloader-Q8Mkp4mzD.exe
2015-01-29 23:01 - 2015-01-29 23:01 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-01-28 10:26 - 2015-01-29 08:26 - 00000000 ____D () C:\Users\Public\Documents\Arc
2015-01-27 00:23 - 2015-01-27 00:23 - 00014464 _____ (Western Digital Technologies) C:\Windows\system32\Drivers\wdcsam64.sys
2015-01-26 12:55 - 2015-01-26 12:56 - 00000000 ____D () C:\Users\Tyrion Lannister\Desktop\SEK Berlin
2015-01-14 09:45 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 09:45 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 09:45 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 09:45 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 09:45 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 09:45 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 09:45 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 09:45 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 09:45 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 09:45 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 09:45 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 09:45 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 09:45 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-05 11:30 - 2009-07-14 05:45 - 00026464 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-05 11:30 - 2009-07-14 05:45 - 00026464 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-05 11:28 - 2012-10-24 19:58 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-02-05 11:28 - 2012-10-24 19:58 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-02-05 11:28 - 2012-10-24 19:58 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-02-05 11:28 - 2011-12-30 17:00 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-05 11:23 - 2012-10-31 15:41 - 00000440 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2015-02-05 11:21 - 2014-09-17 15:40 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-05 11:21 - 2013-02-09 08:40 - 00352322 _____ () C:\Windows\PFRO.log
2015-02-05 11:21 - 2013-02-09 08:40 - 00072486 _____ () C:\Windows\setupact.log
2015-02-05 11:21 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-05 11:20 - 2011-12-30 15:59 - 01651557 _____ () C:\Windows\WindowsUpdate.log
2015-02-05 10:53 - 2014-09-17 15:40 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-05 10:45 - 2013-08-15 21:50 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-05 09:48 - 2014-09-17 15:40 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-05 09:48 - 2014-09-17 15:40 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-02-05 01:05 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-02-05 01:00 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-05 00:14 - 2014-11-09 23:10 - 00000000 ____D () C:\Users\Tyrion Lannister\AppData\Roaming\Verbindungsassistent
2015-02-04 10:28 - 2014-09-17 15:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-02-04 10:28 - 2014-07-07 10:38 - 00001065 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-02-04 10:28 - 2011-12-30 16:10 - 00001017 _____ () C:\Users\Tyrion Lannister\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-02-03 16:21 - 2012-12-05 15:54 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-03 11:07 - 2009-07-14 18:58 - 02799576 _____ () C:\Windows\system32\perfh007.dat
2015-02-03 11:07 - 2009-07-14 18:58 - 00806998 _____ () C:\Windows\system32\perfc007.dat
2015-02-03 11:07 - 2009-07-14 06:13 - 00006472 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-03 00:02 - 2012-10-20 20:37 - 00000000 ____D () C:\Users\Tyrion Lannister\AppData\Roaming\vlc
2015-02-01 22:48 - 2014-12-30 09:12 - 00067728 _____ () C:\Users\Tyrion Lannister\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-01 22:48 - 2014-12-30 09:01 - 00298008 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-31 22:48 - 2014-04-15 15:08 - 00000776 _____ () C:\Windows\system32\.crusader
2015-01-29 23:01 - 2014-05-16 11:03 - 00000000 ____D () C:\ProgramData\Package Cache
2015-01-29 23:01 - 2013-08-05 09:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-01-29 23:01 - 2013-08-05 09:41 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-01-26 02:59 - 2014-10-13 13:20 - 00001250 _____ () C:\Users\Tyrion Lannister\Desktop\Amazon Music.lnk
2015-01-20 08:20 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-15 01:24 - 2013-08-16 00:39 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-15 01:16 - 2011-12-30 19:02 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-06 04:36 - 2011-12-30 16:49 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
==================== Files in the root of some directories =======
2013-08-17 11:13 - 2013-08-17 11:13 - 0003584 _____ () C:\Users\Tyrion Lannister\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-01 11:15 - 2015-01-03 17:41 - 0007606 _____ () C:\Users\Tyrion Lannister\AppData\Local\Resmon.ResmonCfg
2013-08-12 18:24 - 2013-08-12 18:24 - 0005033 _____ () C:\ProgramData\mtbjfghn.xbe
Some content of TEMP:
====================
C:\Users\Tyrion Lannister\AppData\Local\Temp\avgnt.exe
C:\Users\Tyrion Lannister\AppData\Local\Temp\Quarantine.exe
C:\Users\Tyrion Lannister\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-05 09:39
==================== End Of Log ============================ --- --- ---
Hoffe, alles hat geklappt ! |