HonigSenf | 18.04.2014 16:44 | Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.04.2014
Suchlauf-Zeit: 17:17:45
Logdatei: 1.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.18.06
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: scary
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 262233
Verstrichene Zeit: 15 Min, 57 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
Adware.Adpeak, C:\Program Files\002\bukgmhvrux64.exe, 1860, Löschen bei Neustart, [59a7867a9b659a662040a97413f17a86]
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\RrFilterService64.exe, 1112, Löschen bei Neustart, [847cd12f08f8f907d58338320df50bf5]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 10
Adware.Adpeak, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\bukgmhvrux64, In Quarantäne, [59a7867a9b659a662040a97413f17a86],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\INTERFACE\{3408AC0D-510E-4808-8F7B-6B70B1F88534}, In Quarantäne, [ee1249b7d030bc44e02646d12ed438c8],
PUP.Optional.OutBrowse, HKLM\SOFTWARE\CLASSES\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}, In Quarantäne, [69975fa142bed7299e68a671cb3747b9],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\Rr Savings, In Quarantäne, [d42ce61ad12fa060a100bbaf649e936d],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, In Quarantäne, [d927e21efa061be5633fc8a2887a758b],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\rrsavings, In Quarantäne, [04fc8d73f808ab55465a5218b949aa56],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3569910090-1362072758-1005780473-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RrSavings, Löschen bei Neustart, [35cb827e34cccd33cbd9d199f012f40c],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3569910090-1362072758-1005780473-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Rr Savings, Löschen bei Neustart, [08f8b749d12f17e9edbbe08aaa5807f9],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3569910090-1362072758-1005780473-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\rrsavings, Löschen bei Neustart, [ab5529d7728e9c647e290961e51dd828],
PUP.Optional.RRSavings.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RrFilterService64, In Quarantäne, [847cd12f08f8f907d58338320df50bf5],
Registrierungswerte: 2
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [fa0611ef0000c040060eaa6eb54d6c94],
PUP.Optional.VBates, HKLM\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, C:\Program Files\V-bates\Firefox, In Quarantäne, [fa0611ef0000c040060eaa6eb54d6c94]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 29
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter, Löschen bei Neustart, [847cd12f08f8f907d58338320df50bf5],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\defaults, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\defaults\preferences, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\locale, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\addon-kit, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\addon-kit\data, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\addon-kit\lib, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\data, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\event, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\addon, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\dom, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\events, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\private-browsing, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\system, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traits, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\window, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\RrSavings, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\RrSavings\data, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\RrSavings\lib, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\RrSavings\tests, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
Dateien: 93
Adware.Adpeak, C:\Program Files\002\bukgmhvrux64.exe, Löschen bei Neustart, [59a7867a9b659a662040a97413f17a86],
PUP.Optional.Conduit.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\searchplugins\conduit-search.xml, In Quarantäne, [3fc11ae66898c937f84ade950002cf31],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [857b2fd130d0ec142ffd99df689a15eb],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\nfapi.dll, Löschen bei Neustart, [847cd12f08f8f907d58338320df50bf5],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\nfregdrv.exe, In Quarantäne, [847cd12f08f8f907d58338320df50bf5],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\ProtocolFilters.dll, Löschen bei Neustart, [847cd12f08f8f907d58338320df50bf5],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\RrFilterService64.exe, Löschen bei Neustart, [847cd12f08f8f907d58338320df50bf5],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\sample.dll, In Quarantäne, [847cd12f08f8f907d58338320df50bf5],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\bootstrap.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\harness-options.json, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\icon.png, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\install.rdf, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\locales.json, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\defaults\preferences\prefs.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\page-mod.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\private-browsing.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\request.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\addon-kit\lib\windows.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\observer-service.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\api-utils.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\base64.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\byte-streams.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\collection.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\cortex.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\cuddlefish.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\deprecate.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\environment.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\errors.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\events.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\file.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\functional.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\globals.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\heritage.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\hidden-frame.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\light-traits.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\list.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\loader.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\match-pattern.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\memory.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\namespace.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\plain-text-console.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\preferences-service.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\promise.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\querystring.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\runtime.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\sandbox.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\self.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\system.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\text-streams.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\timer.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traceback.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traits.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\unload.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\url.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\uuid.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\window-utils.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\xhr.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\xpcom.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\xul-app.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\event\core.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\event\target.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\addon\runner.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\content-proxy.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\content-worker.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\loader.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\symbiont.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\content\worker.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\dom\events.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\events\assembler.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\core.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\html.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\loader.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\locale.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\l10n\prefs.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\private-browsing\utils.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\system\events.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\events.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\observer.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\tab.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\tabs\utils.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\traits\core.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\data.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\object.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\registry.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\utils\thumbnail.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\window\utils.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\dom.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\loader.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\observer.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\api-utils\lib\windows\tabs.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\RrSavings\data\icon64.png, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
PUP.Optional.RRSavings.A, C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\extensions\RrSavings@jetpack\resources\RrSavings\lib\main.js, In Quarantäne, [728e9a66a55bc13fc198145605fd9f61],
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.023 - Bericht erstellt am 18/04/2014 um 17:28:30
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : scary - V4ND4R
# Gestartet von : D:\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Windows\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}
Ordner Gelöscht : C:\Users\scary\AppData\Local\CrashRpt
Datei Gelöscht : C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\invalidprefs.js
Datei Gelöscht : C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\searchplugins\Plusnetwork.xml
Datei Gelöscht : C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bodddioamolcibagionmmobehnbhiakf
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\Extension.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchProtectINT_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchProtectINT_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_foxit-pdf-reader_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_foxit-pdf-reader_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B302A1BD-0157-49FA-90F1-4E94F22C7B4B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A36867C6-302D-49FC-9D8E-1EB037B5F1AB}
Schlüssel Gelöscht : HKLM\Software\GinyasBrowserCompanion
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{813BA625-B0FA-48D8-9B75-59759C88C219}
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16450
-\\ Mozilla Firefox v28.0 (en-US)
[ Datei : C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\prefs.js ]
Zeile gelöscht : user_pref("{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}.ScriptData_whiteListSearch", "{\"isearch.babylon.com\":\"q\",\"search.imesh.net\":\"q\",\"www.search-results.com\":\"q\",\"home.mywebsearch.com\":\"se[...]
*************************
AdwCleaner[R0].txt - [3081 octets] - [18/04/2014 17:25:57]
AdwCleaner[S0].txt - [2876 octets] - [18/04/2014 17:28:30]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2936 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by scary on 18.04.2014 at 17:33:55.38
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\scary\AppData\Roaming\getrighttogo"
~~~ FireFox
Emptied folder: C:\Users\scary\AppData\Roaming\mozilla\firefox\profiles\68o0lesx.default\minidumps [395 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.04.2014 at 17:39:19.44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by scary (administrator) on V4ND4R on 18-04-2014 17:39:54
Running from D:\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files (x86)\scary\Hama S1\S1_2k.exe
(Dropbox, Inc.) C:\Users\scary\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
() C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\updrgui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\update.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\nvspcap64.dll [1100248 2013-12-10] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2279712 2013-12-10] (NVIDIA Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [2583040 2009-09-21] (VIA)
HKLM-x32\...\Run: [BambooCore] => C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-3569910090-1362072758-1005780473-1000\...\Run: [Steam] => D:\Games\Steam\steam.exe [1821888 2014-02-25] (Valve Corporation)
HKU\S-1-5-21-3569910090-1362072758-1005780473-1000\...\Run: [La_View Mouse] => C:\Program Files (x86)\scary\Hama S1\S1_2k.exe [2887680 2005-11-05] ()
HKU\S-1-5-21-3569910090-1362072758-1005780473-1000\...\MountPoints2: {43cbdfc1-251d-11e2-a502-00252255807d} - F:\Startme.exe
Startup: C:\Users\scary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\scary\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\scary\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xD1A325FE72A6CD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default
FF DefaultSearchEngine: Yahoo
FF SelectedSearchEngine: Yahoo
FF Homepage: hxxp://de.yahoo.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.10 - C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.0.0.1 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Protegere - C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\Extensions\security@protegere.org [2014-04-18]
FF Extension: Adblock Plus - C:\Users\scary\AppData\Roaming\Mozilla\Firefox\Profiles\68o0lesx.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-10-10]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-06-01] ()
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15129376 2013-12-10] (NVIDIA Corporation)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [627992 2014-01-13] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-12] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-25] (Avira Operations GmbH & Co. KG)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [61736 2014-02-28] (NetFilterSDK.com)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39200 2013-12-05] (NVIDIA Corporation)
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S3 AsrCDDrv; \??\C:\Windows\SysWOW64\Drivers\AsrCDDrv.sys [X]
S3 wacommousefilter; system32\DRIVERS\wacommousefilter.sys [X]
S3 wacomvhid; system32\DRIVERS\wacomvhid.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-18 17:39 - 2014-04-18 17:39 - 00000838 _____ () C:\Users\scary\Desktop\JRT.txt
2014-04-18 17:33 - 2014-04-18 17:33 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 17:25 - 2014-04-18 17:28 - 00000000 ____D () C:\AdwCleaner
2014-04-18 17:00 - 2014-04-18 17:32 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-18 17:00 - 2014-04-18 17:00 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-18 17:00 - 2014-04-18 17:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-18 17:00 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-18 17:00 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-18 17:00 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-18 16:42 - 2014-04-18 16:42 - 00001268 _____ () C:\Users\scary\Desktop\Revo Uninstaller.lnk
2014-04-18 16:42 - 2014-04-18 16:42 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-18 15:55 - 2014-04-18 17:39 - 00000000 ____D () C:\FRST
2014-04-18 15:08 - 2014-04-18 15:09 - 00000000 ____D () C:\Program Files\002
2014-04-18 15:08 - 2014-04-18 15:08 - 00000000 ____D () C:\Users\scary\AppData\Roaming\Security System 2
2014-04-18 15:08 - 2014-04-18 15:08 - 00000000 ____D () C:\Users\scary\AppData\Roaming\BupSystem
2014-04-18 14:41 - 2014-04-18 14:41 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-18 14:41 - 2014-04-18 14:41 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-18 14:41 - 2014-04-18 14:41 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-18 14:41 - 2014-04-18 14:41 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-18 14:41 - 2014-04-18 14:41 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-18 14:31 - 2014-04-18 14:31 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-04-07 00:35 - 2014-04-07 00:35 - 00001654 _____ () C:\Users\scary\AppData\Local\recently-used.xbel
2014-04-07 00:04 - 2014-04-07 00:04 - 00001011 _____ () C:\Users\Public\Desktop\Inkscape.lnk
2014-04-07 00:04 - 2014-04-07 00:04 - 00000000 ____D () C:\Users\scary\AppData\Roaming\inkscape
2014-04-07 00:01 - 2014-04-07 00:04 - 00000000 ____D () C:\Program Files (x86)\Inkscape
2014-03-29 17:35 - 2014-03-29 17:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-27 18:59 - 2014-04-15 14:26 - 00000053 _____ () C:\Users\scary\Desktop\Neues Textdokument (2).txt
2014-03-24 00:18 - 2014-03-24 22:51 - 00000000 ____D () C:\Users\scary\Documents\PlanetExplorers
2014-03-23 14:33 - 2014-03-23 14:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf
2014-03-23 14:33 - 2014-03-23 14:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_wachidrouter_01009.Wdf
2014-03-23 14:33 - 2014-03-23 14:33 - 00000000 ____D () C:\Program Files\TabletPlugins
2014-03-23 14:33 - 2013-11-12 02:16 - 00090424 _____ (Wacom Technology) C:\Windows\system32\Drivers\wachidrouter.sys
2014-03-23 14:33 - 2013-11-12 02:16 - 00015160 _____ (Wacom Technology) C:\Windows\system32\Drivers\wacomrouterfilter.sys
2014-03-23 14:33 - 2013-11-12 02:16 - 00014136 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\hidkmdf.sys
2014-03-23 14:33 - 2012-04-12 00:34 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\wdfcoinstaller01009.dll
2014-03-23 14:33 - 2012-04-12 00:34 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wdfcoinstaller01009.dll
==================== One Month Modified Files and Folders =======
2014-04-18 17:39 - 2014-04-18 17:39 - 00000838 _____ () C:\Users\scary\Desktop\JRT.txt
2014-04-18 17:39 - 2014-04-18 15:55 - 00000000 ____D () C:\FRST
2014-04-18 17:39 - 2009-07-14 06:51 - 00675019 _____ () C:\Windows\setupact.log
2014-04-18 17:38 - 2009-07-14 06:45 - 00014368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-18 17:38 - 2009-07-14 06:45 - 00014368 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-18 17:34 - 2009-07-14 19:58 - 00698688 _____ () C:\Windows\system32\perfh007.dat
2014-04-18 17:34 - 2009-07-14 19:58 - 00148828 _____ () C:\Windows\system32\perfc007.dat
2014-04-18 17:34 - 2009-07-14 07:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-18 17:33 - 2014-04-18 17:33 - 00000000 ____D () C:\Windows\ERUNT
2014-04-18 17:32 - 2014-04-18 17:00 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-18 17:30 - 2012-10-10 01:55 - 00000000 ____D () C:\Users\scary\AppData\Roaming\Dropbox
2014-04-18 17:30 - 2012-10-09 21:20 - 00000000 ___RD () C:\Users\scary\Documents\My Dropbox
2014-04-18 17:29 - 2012-10-10 01:41 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-18 17:29 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-18 17:28 - 2014-04-18 17:25 - 00000000 ____D () C:\AdwCleaner
2014-04-18 17:28 - 2012-10-10 00:51 - 01954492 _____ () C:\Windows\WindowsUpdate.log
2014-04-18 17:19 - 2014-04-18 15:08 - 00000000 ____D () C:\Program Files\002
2014-04-18 17:19 - 2012-10-10 03:03 - 00294750 _____ () C:\Windows\PFRO.log
2014-04-18 17:00 - 2014-04-18 17:00 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-18 17:00 - 2014-04-18 17:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-18 17:00 - 2012-10-26 22:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-18 16:47 - 2012-10-10 01:27 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-18 16:42 - 2014-04-18 16:42 - 00001268 _____ () C:\Users\scary\Desktop\Revo Uninstaller.lnk
2014-04-18 16:42 - 2014-04-18 16:42 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-18 15:33 - 2012-10-10 15:29 - 00000000 ____D () C:\Users\scary\AppData\Roaming\TS3Client
2014-04-18 15:08 - 2014-04-18 15:08 - 00000000 ____D () C:\Users\scary\AppData\Roaming\Security System 2
2014-04-18 15:08 - 2014-04-18 15:08 - 00000000 ____D () C:\Users\scary\AppData\Roaming\BupSystem
2014-04-18 14:42 - 2014-01-12 14:38 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-18 14:41 - 2014-04-18 14:41 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-18 14:41 - 2014-04-18 14:41 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-18 14:41 - 2014-04-18 14:41 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-18 14:41 - 2014-04-18 14:41 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-18 14:41 - 2014-04-18 14:41 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-18 14:31 - 2014-04-18 14:31 - 00000000 ____D () C:\Program Files (x86)\SystemRequirementsLab
2014-04-17 22:57 - 2013-12-16 23:23 - 00000000 ____D () C:\Users\scary\AppData\Local\DayZ
2014-04-17 01:49 - 2012-10-10 01:23 - 00000000 ____D () C:\Users\scary\AppData\Roaming\vlc
2014-04-15 14:26 - 2014-03-27 18:59 - 00000053 _____ () C:\Users\scary\Desktop\Neues Textdokument (2).txt
2014-04-14 23:45 - 2013-08-15 20:36 - 00007608 _____ () C:\Users\scary\AppData\Local\Resmon.ResmonCfg
2014-04-14 18:25 - 2012-10-10 05:37 - 00370359 _____ () C:\Windows\DirectX.log
2014-04-14 17:47 - 2013-12-24 23:29 - 00000000 ____D () C:\Users\scary\AppData\Local\Warframe
2014-04-07 00:35 - 2014-04-07 00:35 - 00001654 _____ () C:\Users\scary\AppData\Local\recently-used.xbel
2014-04-07 00:04 - 2014-04-07 00:04 - 00001011 _____ () C:\Users\Public\Desktop\Inkscape.lnk
2014-04-07 00:04 - 2014-04-07 00:04 - 00000000 ____D () C:\Users\scary\AppData\Roaming\inkscape
2014-04-07 00:04 - 2014-04-07 00:01 - 00000000 ____D () C:\Program Files (x86)\Inkscape
2014-04-04 19:53 - 2014-02-02 21:36 - 00000000 ____D () C:\Users\scary\AppData\Local\Battle.net
2014-04-03 09:51 - 2014-04-18 17:00 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-18 17:00 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-18 17:00 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 23:26 - 2013-03-25 22:19 - 00000000 ____D () C:\Users\scary\AppData\Roaming\Audacity
2014-03-30 10:24 - 2012-10-10 01:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-29 17:35 - 2014-03-29 17:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-24 22:51 - 2014-03-24 00:18 - 00000000 ____D () C:\Users\scary\Documents\PlanetExplorers
2014-03-23 14:33 - 2014-03-23 14:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_wacomrouterfilter_01009.Wdf
2014-03-23 14:33 - 2014-03-23 14:33 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_wachidrouter_01009.Wdf
2014-03-23 14:33 - 2014-03-23 14:33 - 00000000 ____D () C:\Program Files\TabletPlugins
2014-03-23 14:33 - 2013-01-10 16:08 - 00000000 ____D () C:\Program Files (x86)\TabletPlugins
2014-03-23 14:33 - 2013-01-10 16:07 - 00000000 ____D () C:\Program Files\Tablet
2014-03-21 20:23 - 2013-11-29 20:12 - 00000000 ____D () C:\Users\scary\AppData\Roaming\Skype
Some content of TEMP:
====================
C:\Users\scary\AppData\Local\Temp\1_Offer_6.exe
C:\Users\scary\AppData\Local\Temp\6_Offer_16.exe
C:\Users\scary\AppData\Local\Temp\avgnt.exe
C:\Users\scary\AppData\Local\Temp\dxwebsetup.exe
C:\Users\scary\AppData\Local\Temp\Foxit Updater.exe
C:\Users\scary\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\scary\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\scary\AppData\Local\Temp\nv3DVStreaming.dll
C:\Users\scary\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\scary\AppData\Local\Temp\nvStereoApiI.dll
C:\Users\scary\AppData\Local\Temp\nvStInst.exe
C:\Users\scary\AppData\Local\Temp\Quarantine.exe
C:\Users\scary\AppData\Local\Temp\sonarinst.exe
C:\Users\scary\AppData\Local\Temp\SRLDetectionLibrary6108991260442443172.dll
C:\Users\scary\AppData\Local\Temp\Uninstaller-3716.exe
C:\Users\scary\AppData\Local\Temp\Uninstaller-4732.exe
C:\Users\scary\AppData\Local\Temp\vlc-2.0.5-win32.exe
C:\Users\scary\AppData\Local\Temp\vlc-2.0.8-win32.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 00:58
==================== End Of Log ============================ --- --- ---
--- --- --- |