Windows fake security update popup Hallo liebe Leute,
der PC meiner Freundin hat seit gestern ein Problem: Ein fake MS13-052 Security update für Windows poppt immer wieder auf. Dasselbe Problem wurde in diesem Forum bereits beschrieben (siehe http://www.trojaner-board.de/144941-...e-net-4-a.html).
Ein erster FRST scan dürfte was gefunden haben, siehe unten. Könnt ihr mir sagen, wie ich jetzt weitermachen kann?
Vielen Dank!
No1Se Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-12-2013
Ran by Desktop (administrator) on DESKTOP-PC on 12-12-2013 18:24:12
Running from C:\Users\Desktop\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Crawler.com) C:\Program Files\Spyware Terminator\st_rsser.exe
(Rocket Division Software) C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files\AutoInstall\ZD1211B_Auto_Install_CD_Only_Gen_0ACE20FF\AutoEJCD.EXE
(Nuance Communications, Inc.) C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
(shbox.de) C:\Program Files\FreePDF_XP\fpassist.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(Brother Industries, Ltd.) C:\Program Files\Brother\Brmfcmon\BrMfimon.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Bamboo Dock\BambooCore.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
(Crawler.com) C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe
() C:\Program Files\NETGEAR\WNA3100\WNA3100.exe
(Dropbox, Inc.) C:\Users\Desktop\AppData\Roaming\Dropbox\bin\Dropbox.exe
() C:\Users\Desktop\AppData\Local\Temp\tmpf7d38d7c\nup.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avscan.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmpaa6a4693\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmp1fe90a0b\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmp828783a6\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmp0ffc7929\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmpd37e4819\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmp4a2f046b\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmp743a07a9\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmpc168bcee\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmp43109b2f\nup.exe
(loihytgvfd) C:\Users\Desktop\AppData\Local\Temp\tmp3ac37b3a\nup.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AutoEJCD_0ACE20FF] - C:\Program Files\AutoInstall\ZD1211B_Auto_Install_CD_Only_Gen_0ACE20FF\AutoEJCD.EXE [40960 2010-01-19] ()
HKLM\...\Run: [IndexSearch] - C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [46368 2008-07-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PaperPort PTD] - C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-07-09] (Nuance Communications, Inc.)
HKLM\...\Run: [PPort11reminder] - C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe [328992 2007-08-31] (Nuance Communications, Inc.)
HKLM\...\Run: [SSBkgdUpdate] - C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [AdobeCS5ServiceManager] - C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM\...\Run: [SwitchBoard] - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM\...\Run: [BrMfcWnd] - C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe [1159168 2009-05-26] (Brother Industries, Ltd.)
HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\BrCtrCen.exe [114688 2008-12-24] (Brother Industries, Ltd.)
HKLM\...\Run: [FreePDF Assistant] - C:\Program Files\FreePDF_XP\fpassist.exe [385024 2009-09-05] (shbox.de)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 10.0\Reader\reader_sl.exe [35736 2011-01-30] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-10] (Adobe Systems Incorporated)
HKLM\...\Run: [DivXUpdate] - C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-29] ()
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [BambooCore] - C:\Program Files\Bamboo Dock\BambooCore.exe [646744 2013-01-08] ()
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [683576 2013-11-25] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SpywareTerminatorShield] - C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com)
HKLM\...\Run: [SpywareTerminatorUpdater] - C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com)
HKCU\...\Run: [DAEMON Tools Lite] - "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
HKCU\...\Run: [msnmsgr] - C:\Program Files\Windows Live\Messenger\msnmsgr.exe [4272640 2012-09-12] (Microsoft Corporation)
HKCU\...\Run: [AdobeBridge] - [x]
HKCU\...\Run: [Sobeytduot] - C:\Users\Desktop\AppData\Roaming\Ebzapo\ileqs.exe [295556 2013-01-04] (gtfrdeszde)
HKCU\...\Run: [nup] - C:\Users\Desktop\AppData\Local\Temp\tmp3ac37b3a\nup.exe [387717 2013-12-12] (loihytgvfd) <===== ATTENTION
Startup: C:\Users\Desktop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Desktop\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.avira.com/?l=dis&o=APN10263&gct=hp&dc=EU&locale=de_AT
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://at.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-at
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x57149D9F5FF7CB01
URLSearchHook: HKLM - softonic-de3 Toolbar - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
URLSearchHook: HKCU - softonic-de3 Toolbar - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
SearchScopes: HKLM - DefaultScope {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
SearchScopes: HKLM - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2431245
SearchScopes: HKCU - {D3CDF9AA-B31E-441E-B9D1-4AECE7459D41} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-4&o=APN10263&src=crm&q={searchTerms}&locale=&apn_ptnrs=^AGU&apn_dtid=^YYYYYY^YY^AT&apn_uid=c25fef61-3eab-42a3-b0e1-c0ed310bb7b5&apn_sauid=799C5281-FB1B-48EB-BF2E-DA384F28464D
BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
BHO: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Adobe Reader - {147FEC3F-6DE9-437C-8FC1-6B8A20AA0A72} - C:\Users\Desktop\AppData\Roaming\AdobeReader\IE\AdobeReader.dll (Adobe Systems, Incorporated)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: softonic-de3 Toolbar - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
Toolbar: HKLM - softonic-de3 Toolbar - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
Toolbar: HKCU - softonic-de3 Toolbar - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Program Files\softonic-de3\tbsoft.dll (Conduit Ltd.)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: 127.0.0.1 activate.adobe.com
Tcpip\Parameters: [DhcpNameServer] 195.34.133.21 212.186.211.21
FireFox:
========
FF ProfilePath: C:\Users\Desktop\AppData\Roaming\Mozilla\Firefox\Profiles\fxyjbvp1.default
FF Homepage: hxxp://search.avira.com/?l=dis&o=APN10263&gct=hp&dc=EU&locale=de_AT
FF SelectedSearchEngine: Ask.com
FF SearchEngineOrder.1: Ask.com
FF DefaultSearchEngine: Ask.com
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF Plugin: @divx.com/DivX Player Plugin,version=1.0.0 - C:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll No File
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @graphisoft.com/GDL Web Plug-in - C:\Program Files\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE)
FF Plugin: @java.com/DTPlugin,version=10.7.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.7.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF SearchPlugin: C:\Users\Desktop\AppData\Roaming\Mozilla\Firefox\Profiles\fxyjbvp1.default\searchplugins\askcom.xml
FF Extension: Skype extension for Firefox - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF Extension: Adobe Reader - C:\Program Files\Mozilla Firefox\extensions\{b677fa16-ac2f-410c-8ea5-3bc98ed515d3}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF HKLM\...\Firefox\Extensions: [{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}] - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
FF Extension: Adobe Contribute Toolbar - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}
Chrome:
=======
CHR DefaultSearchKeyword: google.at
CHR DefaultSearchProvider: Google
CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\31.0.1650.63\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.4) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
CHR Plugin: (ArchiCAD) - C:\Program Files\GRAPHISOFT\GDLWebControl\npGDLMozilla.dll (Graphisoft SE)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U7) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (McAfee Security Scanner +) - C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
CHR Plugin: (Silverlight Plug-In) - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll No File
CHR Plugin: (Microsoft Office Live Plug-in for Firefox) - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (WacomTabletPlugin) - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
CHR Plugin: (Photo Gallery) - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.70.11) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Desktop\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Desktop\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Desktop\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Desktop\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (Google Wallet) - C:\Users\Desktop\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0
CHR Extension: (Gmail) - C:\Users\Desktop\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-25] (Avira Operations GmbH & Co. KG)
S2 gupdate1ca8171fbc6f74b; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2009-12-20] (Google Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.)
R2 ST2012_Svc; C:\Program Files\Spyware Terminator\st_rsser.exe [587912 2013-04-03] (Crawler.com)
R2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software)
R2 WSWNA3100; C:\Program Files\NETGEAR\WNA3100\WifiSvc.exe [303360 2011-12-07] ()
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [526208 2012-11-14] (Wacom Technology, Corp.)
S2 ANSYS FLEXlm license manager; C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe [x]
S2 Flexlm Service 1; C:\Program Files\ANSYS Inc\Shared Files\Licensing\intel\lmgrd.exe [x]
==================== Drivers (Whitelisted) ====================
R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [12400 2007-12-17] ()
R1 ASPI32; C:\Windows\System32\Drivers\ASPI32.sys [25244 1999-09-10] (Adaptec)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-08] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137208 2013-11-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 BCMH43XX; C:\Windows\System32\DRIVERS\bcmwlhigh6.sys [1093888 2011-12-12] (Broadcom Corporation)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
S3 hidkmdf; C:\Windows\System32\DRIVERS\hidkmdf.sys [11680 2012-10-12] (Windows (R) Win 7 DDK provider)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
S3 NPF; C:\Windows\System32\DRIVERS\npf.sys [50704 2010-02-03] (CACE Technologies, Inc.)
R0 SCMNdisP; C:\Windows\System32\DRIVERS\scmndisp.sys [21472 2011-07-22] (Windows (R) Win 7 DDK provider)
R0 speedfan; C:\Windows\System32\speedfan.sys [5248 2006-09-24] (Windows (R) 2000 DDK provider)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [691696 2010-04-04] (Duplex Secure Ltd.)
R1 sp_rsdrv2; C:\Windows\system32\drivers\sp_rsdrv2.sys [32768 2011-06-21] ()
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-02-23] (Avira GmbH)
S3 WacHidRouter; C:\Windows\System32\DRIVERS\wachidrouter.sys [69024 2012-10-12] (Wacom Technology)
S3 wacomrouterfilter; C:\Windows\System32\DRIVERS\wacomrouterfilter.sys [13728 2012-10-12] (Wacom Technology)
S2 adfs; No ImagePath
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-12 18:24 - 2013-12-12 18:24 - 00022222 _____ C:\Users\Desktop\Desktop\FRST.txt
2013-12-12 18:22 - 2013-12-12 18:22 - 00022300 _____ C:\Users\Desktop\Downloads\Addition.txt
2013-12-12 18:20 - 2013-12-12 18:23 - 00022224 _____ C:\Users\Desktop\Downloads\FRST.txt
2013-12-12 18:20 - 2013-12-12 18:20 - 00000000 ____D C:\FRST
2013-12-12 18:18 - 2013-12-12 18:19 - 01060373 _____ (Farbar) C:\Users\Desktop\Desktop\FRST.exe
2013-12-12 03:05 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-12 03:05 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-12 03:05 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-12 03:05 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-12 03:05 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-12 03:05 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-12 03:05 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-12 03:05 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-12 03:05 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-12 03:05 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-12 03:05 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-12 03:05 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-12 03:05 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-12 03:05 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-12 03:05 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-12 03:05 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-12 03:05 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-12 03:05 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-12 03:05 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-11 19:30 - 2013-12-12 18:00 - 00000000 ____D C:\ProgramData\Spyware Terminator
2013-12-11 19:30 - 2013-12-11 19:30 - 00001008 _____ C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
2013-12-11 19:30 - 2013-12-11 19:30 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Spyware Terminator
2013-12-11 19:30 - 2013-12-11 19:30 - 00000000 ____D C:\Program Files\Spyware Terminator
2013-12-11 19:30 - 2011-06-21 11:24 - 00032768 _____ C:\Windows\system32\Drivers\sp_rsdrv2.sys
2013-12-11 19:28 - 2013-12-11 19:28 - 05049344 _____ (Crawler.com ) C:\Users\Desktop\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2013-12-11 03:43 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-11 03:43 - 2013-10-30 02:27 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-11 03:43 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-11 03:43 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-11 03:43 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-11 03:43 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-11 03:43 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-11 03:43 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-11 03:43 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-10 21:04 - 2013-12-10 21:04 - 00359044 _____ C:\ProgramData\nup.exe
2013-12-10 15:22 - 2013-12-10 15:38 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Laecmy
2013-12-10 15:22 - 2013-12-10 15:22 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Eras
2013-12-10 15:22 - 2013-12-10 15:22 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Ebzapo
2013-11-30 23:28 - 2013-11-30 23:28 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-11-30 23:28 - 2013-11-30 23:28 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-30 23:28 - 2013-11-30 23:28 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-30 23:28 - 2013-11-30 23:28 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-30 23:28 - 2013-11-30 23:28 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-30 23:28 - 2013-11-30 23:28 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-30 23:27 - 2013-11-30 23:30 - 00012053 _____ C:\Windows\IE11_main.log
2013-11-14 19:22 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2013-11-14 19:22 - 2013-10-12 03:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2013-11-14 19:22 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2013-11-14 19:22 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-11-14 19:22 - 2013-10-03 02:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2013-11-14 19:22 - 2013-09-25 03:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2013-11-14 19:22 - 2013-09-25 03:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2013-11-14 19:22 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2013-11-14 19:22 - 2013-09-25 02:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2013-11-14 19:22 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2013-11-14 19:22 - 2013-09-25 02:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2013-11-14 19:22 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2013-11-14 19:22 - 2013-09-25 01:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2013-11-14 19:22 - 2013-09-25 01:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2013-11-14 19:22 - 2013-07-04 13:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
==================== One Month Modified Files and Folders =======
2013-12-12 18:24 - 2013-12-12 18:24 - 00022222 _____ C:\Users\Desktop\Desktop\FRST.txt
2013-12-12 18:23 - 2013-12-12 18:20 - 00022224 _____ C:\Users\Desktop\Downloads\FRST.txt
2013-12-12 18:22 - 2013-12-12 18:22 - 00022300 _____ C:\Users\Desktop\Downloads\Addition.txt
2013-12-12 18:20 - 2013-12-12 18:20 - 00000000 ____D C:\FRST
2013-12-12 18:19 - 2013-12-12 18:18 - 01060373 _____ (Farbar) C:\Users\Desktop\Desktop\FRST.exe
2013-12-12 18:00 - 2013-12-11 19:30 - 00000000 ____D C:\ProgramData\Spyware Terminator
2013-12-12 17:47 - 2013-02-25 13:20 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-12-12 17:44 - 2009-12-20 13:51 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-12 15:26 - 2012-06-21 09:46 - 00000000 ____D C:\Users\Desktop\AppData\Local\Windows Live
2013-12-12 15:21 - 2010-09-02 15:38 - 01851838 _____ C:\Windows\WindowsUpdate.log
2013-12-12 09:44 - 2009-12-20 13:51 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-12 08:10 - 2009-07-14 05:34 - 00024192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-12 08:10 - 2009-07-14 05:34 - 00024192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-12 08:08 - 2010-11-13 10:07 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Dropbox
2013-12-12 08:07 - 2010-09-02 15:48 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-12 08:03 - 2010-11-13 10:10 - 00000000 ___RD C:\Users\Desktop\Documents\My Dropbox
2013-12-12 08:02 - 2009-11-23 17:30 - 00000000 ____D C:\Users\Desktop\Tracing
2013-12-12 08:01 - 2012-11-18 20:16 - 00000000 ____D C:\ProgramData\NVIDIA
2013-12-12 08:01 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-12-12 08:01 - 2009-07-14 05:39 - 19066857 _____ C:\Windows\setupact.log
2013-12-12 04:00 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache
2013-12-12 03:24 - 2009-07-14 05:33 - 03822928 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-12 03:22 - 2009-11-10 21:21 - 00224234 _____ C:\Windows\PFRO.log
2013-12-12 03:21 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-12-12 03:06 - 2009-07-14 03:04 - 00000499 _____ C:\Windows\win.ini
2013-12-12 03:04 - 2013-08-14 22:45 - 00000000 ____D C:\Windows\system32\MRT
2013-12-12 03:01 - 2010-11-24 12:25 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-11 19:30 - 2013-12-11 19:30 - 00001008 _____ C:\Users\Public\Desktop\Spyware Terminator 2012.lnk
2013-12-11 19:30 - 2013-12-11 19:30 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Spyware Terminator
2013-12-11 19:30 - 2013-12-11 19:30 - 00000000 ____D C:\Program Files\Spyware Terminator
2013-12-11 19:28 - 2013-12-11 19:28 - 05049344 _____ (Crawler.com ) C:\Users\Desktop\Downloads\SpywareTerminatorSetup_3.0.0.82.exe
2013-12-11 17:47 - 2013-02-25 13:20 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-12-11 17:47 - 2013-02-25 13:20 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-12-10 21:04 - 2013-12-10 21:04 - 00359044 _____ C:\ProgramData\nup.exe
2013-12-10 15:38 - 2013-12-10 15:22 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Laecmy
2013-12-10 15:22 - 2013-12-10 15:22 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Eras
2013-12-10 15:22 - 2013-12-10 15:22 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Ebzapo
2013-12-08 15:05 - 2013-02-23 13:00 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2013-11-30 23:30 - 2013-11-30 23:27 - 00012053 _____ C:\Windows\IE11_main.log
2013-11-30 23:28 - 2013-11-30 23:28 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-11-30 23:28 - 2013-11-30 23:28 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-11-30 23:28 - 2013-11-30 23:28 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-11-30 23:28 - 2013-11-30 23:28 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-11-30 23:28 - 2013-11-30 23:28 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-11-30 23:28 - 2013-11-30 23:28 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-11-30 23:28 - 2013-11-30 23:28 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-11-30 23:28 - 2013-11-30 23:28 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-11-26 11:11 - 2013-12-12 03:05 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-11-26 10:23 - 2013-12-12 03:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-11-26 10:22 - 2013-12-12 03:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-11-26 09:53 - 2013-12-12 03:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-11-26 09:52 - 2013-12-12 03:05 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-11-26 09:38 - 2013-12-12 03:05 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-11-26 09:38 - 2013-12-12 03:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-11-26 09:36 - 2013-12-12 03:05 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-11-26 09:32 - 2013-12-12 03:05 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-11-26 09:29 - 2013-12-12 03:05 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-11-26 09:29 - 2013-12-12 03:05 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-11-26 09:28 - 2013-12-12 03:05 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-11-26 09:16 - 2013-12-12 03:05 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-11-26 09:13 - 2013-12-12 03:05 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-11-26 08:32 - 2013-12-12 03:05 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-11-26 08:26 - 2013-12-12 03:05 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-11-26 07:34 - 2013-12-12 03:05 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-11-26 07:33 - 2013-12-12 03:05 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-11-26 07:27 - 2013-12-12 03:05 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-11-25 17:05 - 2013-05-08 07:02 - 00067680 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2013-11-25 17:05 - 2013-02-23 13:00 - 00137208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2013-11-25 17:05 - 2013-02-23 13:00 - 00037352 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2013-11-24 18:42 - 2010-09-10 11:57 - 00051000 _____ C:\fpRedmon.log
2013-11-24 18:42 - 2010-09-10 11:57 - 00000000 ____D C:\Users\Desktop\AppData\Local\FreePDF_XP
2013-11-19 10:25 - 2009-11-10 19:35 - 00000000 ____D C:\Users\Desktop\AppData\Roaming\Skype
2013-11-12 03:07 - 2013-12-11 03:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
Files to move or delete:
====================
C:\Users\Desktop\AppData\Local\Temp\tmp3ac37b3a\nup.exe
C:\ProgramData\nup.exe
C:\Users\Desktop\install_flash_player.exe
C:\Users\Desktop\ProTeXt-2.2.1-102109.exe
C:\Users\Desktop\SkypeSetup.exe
C:\Users\Desktop\vlc-1.0.5-win32.exe
C:\Users\Desktop\wlsetup-web.exe
Some content of TEMP:
====================
C:\Users\Desktop\AppData\Local\Temp\AcDeltree.exe
C:\Users\Desktop\AppData\Local\Temp\ApnStub.exe
C:\Users\Desktop\AppData\Local\Temp\AskSLib.dll
C:\Users\Desktop\AppData\Local\Temp\avgnt.exe
C:\Users\Desktop\AppData\Local\Temp\contentDATs.exe
C:\Users\Desktop\AppData\Local\Temp\DivXSetup.exe
C:\Users\Desktop\AppData\Local\Temp\ffmpeg15.exe
C:\Users\Desktop\AppData\Local\Temp\FlashPlayerUpdate.exe
C:\Users\Desktop\AppData\Local\Temp\Fox1E4C.exe
C:\Users\Desktop\AppData\Local\Temp\InstallAX.exe
C:\Users\Desktop\AppData\Local\Temp\InstallPlugin.exe
C:\Users\Desktop\AppData\Local\Temp\jre-6u23-windows-i586-iftw-rv.exe
C:\Users\Desktop\AppData\Local\Temp\jre-6u24-windows-i586-iftw-rv.exe
C:\Users\Desktop\AppData\Local\Temp\jre-7u5-windows-i586-iftw.exe
C:\Users\Desktop\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
C:\Users\Desktop\AppData\Local\Temp\menu.exe
C:\Users\Desktop\AppData\Local\Temp\mpsetup.exe
C:\Users\Desktop\AppData\Local\Temp\qt-mt332.dll
C:\Users\Desktop\AppData\Local\Temp\qt-mt337.dll
C:\Users\Desktop\AppData\Local\Temp\SecurityScan_Release.exe
C:\Users\Desktop\AppData\Local\Temp\setup.exe
C:\Users\Desktop\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Desktop\AppData\Local\Temp\softonic-de3.exe
C:\Users\Desktop\AppData\Local\Temp\unicows.dll
C:\Users\Desktop\AppData\Local\Temp\WiseShell32Utils.dll
C:\Users\Desktop\AppData\Local\Temp\wlsetup-cvr.exe
C:\Users\Desktop\AppData\Local\Temp\_is54B4.exe
C:\Users\Desktop\AppData\Local\Temp\_is78F7.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-10 18:01
==================== End Of Log ============================ |