Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 27.04.2014 05:10:05, SYSTEM, SENEL-PC, Protection, Malware Protection, Starting,
Protection, 27.04.2014 05:10:05, SYSTEM, SENEL-PC, Protection, Malware Protection, Started,
Protection, 27.04.2014 05:10:05, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Starting,
Protection, 27.04.2014 05:10:09, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Started,
Update, 27.04.2014 05:10:35, SYSTEM, SENEL-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 27.04.2014 05:10:44, SYSTEM, SENEL-PC, Manual, Malware Database, 2014.3.4.9, 2014.4.27.1,
Update, 27.04.2014 05:10:50, SYSTEM, SENEL-PC, Manual, program, 2.0.0.1000, 2.0.1.1004,
Protection, 27.04.2014 05:11:20, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Stopping,
Protection, 27.04.2014 05:11:20, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Stopped,
Protection, 27.04.2014 05:11:20, SYSTEM, SENEL-PC, Protection, Malware Protection, Stopping,
Protection, 27.04.2014 05:11:21, SYSTEM, SENEL-PC, Protection, Malware Protection, Stopped,
Protection, 27.04.2014 05:11:35, SYSTEM, SENEL-PC, Protection, Malware Protection, Starting,
Protection, 27.04.2014 05:11:35, SYSTEM, SENEL-PC, Protection, Malware Protection, Started,
Protection, 27.04.2014 05:11:35, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Starting,
Protection, 27.04.2014 05:11:35, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Started,
Update, 27.04.2014 05:11:39, SYSTEM, SENEL-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 27.04.2014 05:11:43, SYSTEM, SENEL-PC, Manual, Malware Database, 2014.3.4.9, 2014.4.27.1,
Protection, 27.04.2014 05:11:44, SYSTEM, SENEL-PC, Protection, Refresh, Starting,
Protection, 27.04.2014 05:11:44, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Stopping,
Protection, 27.04.2014 05:11:44, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Stopped,
Protection, 27.04.2014 05:11:49, SYSTEM, SENEL-PC, Protection, Refresh, Success,
Protection, 27.04.2014 05:11:49, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Starting,
Protection, 27.04.2014 05:11:49, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Started,
Detection, 27.04.2014 05:16:46, SYSTEM, SENEL-PC, Protection, Malware Protection, File, PUP.Optional.NewTab.A, C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx, Quarantine, [cd804ce3e5967db920356022ed15f40c]
Detection, 27.04.2014 05:42:18, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, IP, 173.193.227.115, creoads.com, 55830, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 27.04.2014 05:42:18, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, IP, 173.193.227.115, creoads.com, 55830, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 27.04.2014 05:42:19, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, IP, 173.193.227.115, creoads.com, 55833, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Protection, 27.04.2014 06:50:42, SYSTEM, SENEL-PC, Protection, Malware Protection, Starting,
Protection, 27.04.2014 06:50:42, SYSTEM, SENEL-PC, Protection, Malware Protection, Started,
Protection, 27.04.2014 06:50:43, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Starting,
Protection, 27.04.2014 06:51:20, SYSTEM, SENEL-PC, Protection, Malicious Website Protection, Started,
(end) Code:
# AdwCleaner v3.204 - Bericht erstellt am 27/04/2014 um 07:13:02
# Aktualisiert 26/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Senel - SENEL-PC
# Gestartet von : C:\Users\Senel\Desktop\Programme\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Program Files (x86)\Systweak Support Dock
Ordner Gelöscht : C:\Program Files (x86)\WinZip Registry Optimizer
Ordner Gelöscht : C:\Program Files (x86)\Common Files\Umbrella
Ordner Gelöscht : C:\Windows\SysWOW64\AI_RecycleBin
Ordner Gelöscht : C:\Users\Administrator\AppData\LocalLow\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Users\Ridi\AppData\LocalLow\AVG SafeGuard toolbar
Ordner Gelöscht : C:\Users\Senel\AppData\Local\apn
Ordner Gelöscht : C:\Users\Senel\AppData\Local\b1e
Ordner Gelöscht : C:\Users\Senel\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Senel\AppData\Local\genienext
Ordner Gelöscht : C:\Users\Senel\AppData\Local\Ilivid Player
Ordner Gelöscht : C:\Users\Senel\AppData\Local\lollipop
Ordner Gelöscht : C:\Users\Senel\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Senel\AppData\Local\PackageAware
Ordner Gelöscht : C:\Users\Senel\AppData\Local\PutLockerDownloader
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\Delta
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\FoxTab
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\ilividtoolbarguid
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\incredibar.com
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\PriceGong
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\searchquband
Ordner Gelöscht : C:\Users\Senel\AppData\LocalLow\searchresultstb
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\adawaretb
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\blekko
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\DesktopIconForAmazon
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\iWin
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\OCS
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\PerformerSoft
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\searchquband
Ordner Gelöscht : C:\Users\Senel\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm
Ordner Gelöscht : C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\hahpjplbmicfkmoccokbjejahjjpnena
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Ordner Gelöscht : C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkndmigholgfjlniaohblojbhgjbkakn
[!] Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc
[!] Ordner Gelöscht : C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhphemoobgnikcoofkgackkaimpfmenm
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Senel\AppData\Local\Temp\Uninstall.exe
Datei Gelöscht : C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\user.js
Datei Gelöscht : C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\Profiles\p8bg8o9l.default\user.js
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\user.js
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Public\Desktop\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Senel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
Verknüpfung Desinfiziert : C:\Users\Senel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
Verknüpfung Desinfiziert : C:\Users\Senel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Senel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
Verknüpfung Desinfiziert : C:\Users\Senel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk
Verknüpfung Desinfiziert : C:\Users\Senel\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\aiennapmieppnpfhhogglccgepbdajan
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\bhphemoobgnikcoofkgackkaimpfmenm
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bhphemoobgnikcoofkgackkaimpfmenm
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\leocdeigfnkaojcapikdjcdbedcjmffc
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ogccgbmabaphcakpiclgcnmcnimhokcj
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\pbiamblgmkgbcgbcgejjgebalncpmhnp
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\BrowserConnection.dll
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\iMesh_V11_en_Setup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Applications\iMeshV11.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iLividIEHelper.DNSGuard
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iLividIEHelper.DNSGuard.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Movie2KDownloader
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Babylon_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonTC_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BabylonTC_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BundleSweetIMSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ConduitInstaller_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividMediaBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetupV1_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_V11_en_Setup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\iMesh_V11_en_Setup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\IncredibarToolbar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\QuickShare_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Searchqu Toolbar uninstall_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SearchquMediaBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SetupDataMngr_Searchqu_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetpacksupdatemanager_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SweetPacksUpdateManager_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_samsung-kies_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_samsung-kies_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{01994268-3C10-4044-A1EA-7A9C1B739A11}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{50F7F0BE-31BA-4145-BD8B-6B0DECFED804}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D97A8234-F2A2-4AD4-91D5-FECDB2C553AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02C9C7B0-C7C8-4AAC-A9E4-55295BF60F8F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0398B101-6DA7-473F-A290-17D2FBC88CC0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0CC36196-8589-4B80-A771-D659411D7F90}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{143D96F9-EB64-48B3-B192-91C2C41A1F43}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{14F7D91F-F669-45C9-9F42-BACBFDB86EAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{187A6488-6E71-4A2A-B118-7BEFBFE58257}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2D065204-A024-4C39-8A38-EE7078EC7ACF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{30F5476C-677B-4DB0-B397-51F5BFD86840}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3223F2FB-D9B9-45FC-9D66-CD717FFA4EE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{351798B1-C1D2-45AB-92B4-4D6C2D6AB5AF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3AEA1BEF-6195-46F4-ACA2-0ED14F7EFA1B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{3D7F9AC3-BAC3-4E51-81D7-D121D79E550A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4498C5E9-93C6-4142-B6BE-F0C6DC48B77A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{479BF2D6-E362-4A99-B1AB-BC764D7B97AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{492A108F-51D0-4BD8-899D-AD4AB2893064}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4B6D6E60-FBD2-4E79-BF4B-886BC98F1797}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{60893E02-2E5B-43F9-A93A-BAD60C2DF6EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6D39931F-451E-4BDD-BAF4-37FB96DBBA5D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{76C684D2-C35D-4284-976A-D862F53ADB81}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{796D822A-C3F9-4A97-BAAB-42FE7628EA63}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{79EF3691-EC1A-4705-A01A-D2E36EC11758}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82F41418-8E64-47EB-A7F1-4702A974D289}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{85D920CE-63A7-46DC-8992-41D1D2E07FAD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{895ED5E8-ABB4-40C3-A0CA-2571964268E2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8AAC123A-1959-4A45-BFC5-E2D50783098A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9FF9AE6F-4553-41A7-B645-B0E88850EABF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A07956CD-81F8-4A03-B524-5D87E690DC83}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B5E3B26B-6E5C-4865-A63D-58D04B10E245}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B84D2DC5-42B2-4E5E-BF61-7B48152FF8EF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B89D5309-0367-4494-A92F-3D4C94F88307}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C014EBF8-8854-448B-B5A4-557C4090EDCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C31191DB-2F64-464C-B97C-6AC81ACB7AAC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C342C7A7-F622-4EF3-8B7F-ABB9FBE73F14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C4765B07-BC2F-477B-925C-B2BF24887823}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C875C0A1-09E3-48D5-9F8E-BD337796FD14}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD126DA6-FF5B-4181-AC13-54A62240D2FA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CE4DB5A3-58E6-41F1-8761-47238DF4F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DD438708-AAB4-422D-A322-B619589F5680}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E812AE43-7799-4E67-8CF8-4104297A2D16}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F0BAAEC7-9AE0-49FF-9C4B-86E774FF397F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F92193FD-2243-4401-9ACC-49FF30885898}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FD21B8A2-910B-45AC-9C10-45E6A8B84984}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{75E8DA27-44AF-40AE-927C-F2EEC99D65B1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{78F3A323-798E-4AEA-9A57-88F4B05FD5DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7AC3E13B-3BCA-4158-B330-F66DBB03C1B5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{8F97BFF8-488B-4107-BCEE-B161AB4E4183}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1B48071-416D-474E-A13B-BE5456E7FC31}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BFF6B2CA-366C-4A90-B685-D87776DEB0D2}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47C0-9269-B4C6572FD61A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{EEE6C35B-6118-11DC-9C72-001320C79847}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Schlüssel Gelöscht : HKCU\Software\APN DTX
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\ilivid
Schlüssel Gelöscht : HKCU\Software\ilividtoolbarguid
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ilividtoolbarguid
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\searchqutoolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\iLividSRTB
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DataMngr
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\InstalledThirdPartyPrograms
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Speedchecker Limited
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v
[ Datei : C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "AVG Secure Search");
[ Datei : C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\Profiles\p8bg8o9l.default\prefs.js ]
-\\ Google Chrome v34.0.1847.116
[ Datei : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\preferences ]
[ Datei : C:\Users\Ridi\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
[ Datei : C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.awesomehp.com/web/?type=ds&ts=1391479063&from=epom2&uid=ST3250310AS_6RYCW312XXXX6RYCW312&q={searchTerms}
*************************
AdwCleaner[R0].txt - [26823 octets] - [27/04/2014 07:12:19]
AdwCleaner[S0].txt - [23635 octets] - [27/04/2014 07:13:02]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [23696 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Senel on 27.04.2014 at 7:18:48,34
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\adawarebp_rasdlg
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\foxydeal_rasapi32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\foxydeal_rasmancs
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mconduitinstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\mconduitinstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetupV1 (1)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\iLividSetupV1 (1)_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\mconduitinstaller_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\mconduitinstaller_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetupV1 (1)_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\iLividSetupV1 (1)_RASMANCS
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\browser manager"
Successfully deleted: [Folder] "C:\ProgramData\installbrainservice"
Successfully deleted: [Folder] "C:\ProgramData\sweetim"
Successfully deleted: [Folder] "C:\ProgramData\wincert"
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{0337BA18-CC17-478A-B591-A7BFCD1C6CB3}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{0ECD913B-5653-4B7A-ADB9-B694C7B8B72B}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{0F7DF3BD-FE28-49EB-A8EC-BA5195FFDE28}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{1FCBC7A9-799F-47CB-AF0B-889C4FA550FB}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{2607C313-799F-46B9-BA44-E784E07A8749}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{3737E677-9ED1-4064-B401-372DC0839927}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{4327ABDA-5AC5-4EBF-8EF4-E02EB0774151}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{59FAC615-7E4F-4889-966C-3BDEF26BE300}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{5DE52149-E36E-4DEC-B229-5BED7144755A}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{63DC9255-7DA1-4BDC-8681-9AFE8DCF532E}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{7026B23B-8349-4C8A-95C4-F065BC59AE2F}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{70A06BC0-198A-4BC8-84F8-FA0E855DDCEA}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{7360A264-1DD7-4FEB-8D42-1E05D653D353}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{75CF96F5-1D91-4D1D-AA87-299398ABFB2D}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{849A314C-CF32-4856-B601-81E06641C679}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{87B8C2AC-9FA6-4621-A5F7-EA4DE6B7752F}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{91C94504-D0F1-412A-9999-3319ED8AD819}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{9265967C-2705-4280-8075-B6105445AEBC}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{9C6D602C-EB1E-4383-B0FB-B778D6B06AC9}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{9CDF6258-2DBB-481D-8693-6DA132626B10}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{A46794CA-B90E-400B-868E-6149EE17065C}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{A48C8C5A-EEEB-48A9-8775-2DA0F89F4AD4}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{AE0647FD-CC38-4349-B7C7-00A0CB298951}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{B0B224E1-0806-4758-81B3-C336C9BB76B5}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{B45149F7-BA1F-47F3-8382-DCC609E838DC}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{B635F96D-F727-41D8-BC5C-5AEABA37D7DE}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{C3DD8984-17E3-493B-B913-3270362B1C71}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{CC44B993-FA41-44EB-B7C8-AC727F962D74}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{E1C65F5B-9E1B-4EA7-BCE8-26283DA1D88C}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{E23374E2-8D12-4182-88EB-6E13F61C3E00}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{F48DC156-6793-4E2C-9E59-9F6B875B4E38}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{FDBF6662-F155-4CAA-BB6A-D8EBD24719F2}
Successfully deleted: [Empty Folder] C:\Users\Senel\appdata\local\{FF1360C3-3D17-44CF-A783-F9F46BADACE7}
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Senel\appdata\local\Google\Chrome\User Data\Default\Extensions\hahpjplbmicfkmoccokbjejahjjpnena
Successfully deleted: [Folder] C:\Users\Senel\appdata\local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 27.04.2014 at 7:27:13,90
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-04-2014 03
Ran by Senel (administrator) on SENEL-PC on 27-04-2014 08:09:50
Running from C:\Users\Senel\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(AVG) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2041192 2012-12-29] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5180432 2014-04-06] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-1969415253-1381297592-3536760822-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-1969415253-1381297592-3536760822-1000\...\Run: [ccleaner] => C:\Program Files\Portable\CCleaner Professional 64-bit v3.26.1888\CCleaner64.exe [5628848 2012-12-19] (Piriform Ltd)
HKU\S-1-5-21-1969415253-1381297592-3536760822-1000\...\MountPoints2: {80d41f16-b3df-11e2-9b7b-00219b3b5af3} - E:\Startme.exe
HKU\S-1-5-21-1969415253-1381297592-3536760822-1000\...\MountPoints2: {fbacd5fe-90ac-11e1-8294-00219b3b5af3} - E:\iStudio.exe
AppInit_DLLs-x32: C:\PROGRA~2\Amazon\AMAZON~1\\AMAZON~3.DLL => "C:\PROGRA~2\Amazon\AMAZON~1\\AMAZON~3.DLL" File Not Found
IFEO\AcroRd32.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\icloud.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\icloudweb.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
IFEO\shellstreamsshortcut.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\digital imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xB312C1B358C6CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: FoxTab - {4DF4AC8C-FFA8-40FF-91F0-EB8389314B78} - C:\Users\Senel\AppData\LocalLow\FoxTab\IE\FoxTab.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - !{c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File
Toolbar: HKLM-x32 - No Name - !{c840e246-6b95-475e-9bd7-caa1c7eca9f2} - No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKCU - No Name - {C840E246-6B95-475E-9BD7-CAA1C7ECA9F2} - No File
Toolbar: HKCU - No Name - {0027DA2D-C9F2-4B0B-AE05-E2CD1BDB6CFF} - No File
Toolbar: HKCU - No Name - {5786D022-540E-4699-B350-B4BE0AE94B79} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\Profiles\p8bg8o9l.default
FF Homepage: user_pref("browser.startup.homepage", );
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.17.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.17.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npNxGameEU.dll No File
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF SearchPlugin: C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\Profiles\p8bg8o9l.default\searchplugins\improvedsearch.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\Profiles\p8bg8o9l.default\Extensions\ich@maltegoetz.de [2013-03-16]
FF Extension: No Name - C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2012-12-24]
FF Extension: No Name - C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\profiles\extensions\searchplugins [2013-03-16]
FF Extension: Movie2kDownloader - C:\Users\Senel\AppData\Roaming\Mozilla\Firefox\profiles\extensions\movie2kdownloader@movie2kdownloader.com.xpi [2012-12-13]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff\
Chrome:
=======
CHR Extension: (ProxTube) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2013-10-25]
CHR Extension: (Docs) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-28]
CHR Extension: (Google Drive) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-28]
CHR Extension: (No Name) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcfjehbfanfhgoehogmbiebedkidedjb [2013-05-12]
CHR Extension: (YouTube) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-28]
CHR Extension: (Google Search) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-28]
CHR Extension: (No Name) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehjkfdmkpocpileolmldepapdjbfegei [2013-12-24]
CHR Extension: (No Name) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkjoiggkbepedjmjjbhhecjiimlckcga [2012-12-20]
CHR Extension: (DvdVideoSoft Free Youtube Download) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp [2012-09-17]
CHR Extension: (Chrome In-App Payments service) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-10-25]
CHR Extension: (FoxTab) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pailhpppfllmijejfccffanaigjphjnb [2013-10-25]
CHR Extension: (Gmail) - C:\Users\Senel\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-28]
CHR HKCU\...\Chrome\Extension: [bcfjehbfanfhgoehogmbiebedkidedjb] - C:\Users\Senel\AppData\Local\CRE\bcfjehbfanfhgoehogmbiebedkidedjb.crx [2013-05-06]
CHR HKCU\...\Chrome\Extension: [fkjoiggkbepedjmjjbhhecjiimlckcga] - C:\Users\Senel\AppData\Local\CRE\fkjoiggkbepedjmjjbhhecjiimlckcga.crx [2012-12-01]
CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [2012-12-01]
CHR HKLM-x32\...\Chrome\Extension: [aakchaleigkohafkfjfjbblobjifikek] - C:\Users\Senel\AppData\LocalLow\proxtube\CHROME\proxtube.crx [2012-04-19]
CHR HKLM-x32\...\Chrome\Extension: [bcfjehbfanfhgoehogmbiebedkidedjb] - C:\Users\Senel\AppData\Local\CRE\bcfjehbfanfhgoehogmbiebedkidedjb.crx [2013-05-06]
CHR HKLM-x32\...\Chrome\Extension: [fkjoiggkbepedjmjjbhhecjiimlckcga] - C:\Users\Senel\AppData\Local\CRE\fkjoiggkbepedjmjjbhhecjiimlckcga.crx [2012-12-01]
CHR HKLM-x32\...\Chrome\Extension: [pailhpppfllmijejfccffanaigjphjnb] - C:\Users\Senel\AppData\LocalLow\FoxTab\CHROME\FoxTab.crx [2012-12-01]
==================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3645456 2014-04-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [291912 2014-03-27] (AVG Technologies CZ, s.r.o.)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4467488 2013-05-29] (INCA Internet Co., Ltd.)
S3 Pml Driver HPZ12; C:\Windows\SysWOW64\HPZipm12.exe [65536 2004-03-18] (HP)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2102072 2013-12-18] (AVG)
S3 xsherlock; C:\Windows\SysWOW64\xsherlock.xem [666720 2012-12-20] (Wellbia.com Co., Ltd.)
==================== Drivers (Whitelisted) ====================
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [237336 2014-04-18] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192792 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [236824 2014-03-27] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [324376 2014-03-27] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130840 2014-03-31] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [32536 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-03-31] (AVG Technologies CZ, s.r.o.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
S3 REN2CAP_DRIVER; C:\Windows\System32\drivers\ren2cap.sys [46728 2011-11-07] ()
R1 Serial; C:\Windows\System32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [560184 2012-08-16] (Duplex Secure Ltd.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2013-12-16] (TuneUp Software)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S2 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]
S3 TKCtrl; \??\C:\Windows\system32\TKCtrl2k64.sys [X]
S3 TKFsAvM; \??\C:\Windows\system32\TKFsAv64.sys [X]
S3 TKFsFtM; \??\C:\Windows\system32\TKFsFt64.sys [X]
S1 TKFWFV; system32\TKFWFV64.sys [X]
S3 TKFWVT; \??\C:\Windows\system32\TKFWVT64.sys [X]
S3 TkIdsVt; \??\C:\Windows\system32\TkIdsVt64.sys [X]
S3 TKPcFt; \??\C:\Windows\system32\TKPcFtCb64.sys [X]
S3 X6va011; \??\C:\Windows\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\Windows\SysWOW64\Drivers\X6va012 [X]
S3 X6va017; \??\C:\Windows\SysWOW64\Drivers\X6va017 [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-27 08:09 - 2014-04-27 08:09 - 00000000 ____D () C:\Users\Senel\Downloads\FRST-OlderVersion
2014-04-27 07:27 - 2014-04-27 07:27 - 00006189 _____ () C:\Users\Senel\Desktop\JRT.txt
2014-04-27 07:18 - 2014-04-27 07:18 - 00000000 ____D () C:\Windows\ERUNT
2014-04-27 07:17 - 2014-04-27 07:17 - 01016261 _____ (Thisisu) C:\Users\Senel\Downloads\JRT.exe
2014-04-27 07:15 - 2014-04-27 07:15 - 00023821 _____ () C:\Users\Senel\Desktop\AdwCleaner[S0].txt
2014-04-27 07:12 - 2014-04-27 07:13 - 00000000 ____D () C:\AdwCleaner
2014-04-27 07:12 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-04-27 06:59 - 2014-04-27 06:59 - 00003592 _____ () C:\Users\Senel\Desktop\mbam.txt
2014-04-27 06:58 - 2014-04-27 06:58 - 00064624 _____ () C:\Users\Senel\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-27 06:50 - 2014-04-27 07:14 - 00000112 _____ () C:\Windows\setupact.log
2014-04-27 06:50 - 2014-04-27 06:50 - 00300104 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-27 06:50 - 2014-04-27 06:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-27 06:49 - 2014-04-27 07:14 - 00001408 _____ () C:\Windows\PFRO.log
2014-04-27 05:10 - 2014-04-27 07:15 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-27 05:09 - 2014-04-27 05:11 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-27 05:09 - 2014-04-27 05:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-27 05:09 - 2014-04-27 05:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-27 05:09 - 2014-04-27 05:09 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Senel\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-27 05:09 - 2014-04-27 05:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-27 05:09 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-27 05:09 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-27 05:09 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-27 04:50 - 2014-04-27 04:50 - 00001268 _____ () C:\Users\Senel\Desktop\Revo Uninstaller.lnk
2014-04-27 04:50 - 2014-04-27 04:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-27 04:49 - 2014-04-27 04:49 - 02617648 _____ (VS Revo Group Ltd.) C:\Users\Senel\Downloads\revosetup194.exe
2014-04-25 18:04 - 2014-04-27 08:10 - 00016013 _____ () C:\Users\Senel\Downloads\FRST.txt
2014-04-25 18:04 - 2014-04-25 18:05 - 00037888 _____ () C:\Users\Senel\Downloads\Addition.txt
2014-04-25 18:03 - 2014-04-27 08:09 - 02061824 _____ (Farbar) C:\Users\Senel\Downloads\FRST64.exe
2014-04-25 18:03 - 2014-04-27 08:09 - 00000000 ____D () C:\FRST
2014-04-23 09:49 - 2014-04-23 09:53 - 00000000 ___HD () C:\Users\Senel\AppData\Local\Pvyjq
2014-04-22 20:10 - 2014-04-23 10:40 - 00000000 ____D () C:\Program Files (x86)\GameforgeLive
2014-04-18 15:01 - 2014-04-18 15:01 - 00237336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-04-13 10:45 - 2014-04-13 10:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\AVG
2014-04-13 10:40 - 2014-04-13 10:40 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\AVG2014
2014-04-13 10:40 - 2014-04-13 10:40 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Avg2014
2014-04-10 21:18 - 2014-04-10 21:18 - 00000000 ____D () C:\Users\Senel\AppData\Local\dumps
2014-04-10 19:20 - 2014-04-10 19:20 - 00000178 _____ () C:\console.log
2014-04-09 12:04 - 2013-12-25 03:22 - 00000000 ____D () C:\Users\Senel\Desktop\Hardcore-RELOADED
2014-04-08 21:58 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-08 21:57 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-08 21:57 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-08 21:57 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-08 21:54 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-08 21:54 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-08 21:54 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-08 21:54 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-08 21:54 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-08 21:54 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-08 21:54 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-08 21:54 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-08 21:54 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-08 21:54 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-08 21:54 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-08 21:54 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-08 21:54 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-08 21:54 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-08 21:54 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-08 21:54 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-08 21:54 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-07 19:01 - 2011-11-07 16:18 - 00046728 _____ () C:\Windows\system32\Drivers\ren2cap.sys
2014-04-01 11:30 - 2014-04-01 11:30 - 00000000 ____D () C:\Program Files\Sony
2014-04-01 11:30 - 2014-04-01 11:30 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-04-01 08:06 - 2014-04-25 09:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-03-31 16:20 - 2014-03-31 16:20 - 00274200 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-03-31 16:06 - 2014-03-31 16:06 - 00130840 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-03-30 00:15 - 2014-03-30 00:15 - 00000000 ____D () C:\Users\Ridi\AppData\Roaming\AVG
2014-03-30 00:10 - 2014-03-30 00:10 - 00000000 ____D () C:\Users\Ridi\AppData\Roaming\AVG2014
2014-03-30 00:10 - 2014-03-30 00:10 - 00000000 ____D () C:\Users\Ridi\AppData\Local\Avg2014
==================== One Month Modified Files and Folders =======
2014-04-27 08:10 - 2014-04-25 18:04 - 00016013 _____ () C:\Users\Senel\Downloads\FRST.txt
2014-04-27 08:09 - 2014-04-27 08:09 - 00000000 ____D () C:\Users\Senel\Downloads\FRST-OlderVersion
2014-04-27 08:09 - 2014-04-25 18:03 - 02061824 _____ (Farbar) C:\Users\Senel\Downloads\FRST64.exe
2014-04-27 08:09 - 2014-04-25 18:03 - 00000000 ____D () C:\FRST
2014-04-27 07:29 - 2011-12-31 20:16 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-27 07:27 - 2014-04-27 07:27 - 00006189 _____ () C:\Users\Senel\Desktop\JRT.txt
2014-04-27 07:21 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-27 07:21 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-27 07:19 - 2011-04-12 09:43 - 00710046 _____ () C:\Windows\system32\perfh007.dat
2014-04-27 07:19 - 2011-04-12 09:43 - 00154482 _____ () C:\Windows\system32\perfc007.dat
2014-04-27 07:19 - 2009-07-14 07:13 - 01650084 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-27 07:18 - 2014-04-27 07:18 - 00000000 ____D () C:\Windows\ERUNT
2014-04-27 07:17 - 2014-04-27 07:17 - 01016261 _____ (Thisisu) C:\Users\Senel\Downloads\JRT.exe
2014-04-27 07:15 - 2014-04-27 07:15 - 00023821 _____ () C:\Users\Senel\Desktop\AdwCleaner[S0].txt
2014-04-27 07:15 - 2014-04-27 05:10 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-27 07:15 - 2011-12-31 20:16 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-27 07:14 - 2014-04-27 06:50 - 00000112 _____ () C:\Windows\setupact.log
2014-04-27 07:14 - 2014-04-27 06:49 - 00001408 _____ () C:\Windows\PFRO.log
2014-04-27 07:14 - 2013-07-18 01:23 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-04-27 07:14 - 2012-04-08 02:45 - 00000434 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-04-27 07:14 - 2012-01-16 17:46 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-27 07:14 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-27 07:14 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\tracing
2014-04-27 07:13 - 2014-04-27 07:12 - 00000000 ____D () C:\AdwCleaner
2014-04-27 07:13 - 2014-03-07 14:35 - 01129455 _____ () C:\Windows\WindowsUpdate.log
2014-04-27 07:13 - 2013-09-17 03:03 - 00001282 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-27 07:13 - 2013-09-17 03:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-27 07:13 - 2012-01-08 12:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-27 07:13 - 2011-12-29 20:31 - 00000995 _____ () C:\Users\Senel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-27 07:11 - 2012-04-26 09:24 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-27 06:59 - 2014-04-27 06:59 - 00003592 _____ () C:\Users\Senel\Desktop\mbam.txt
2014-04-27 06:58 - 2014-04-27 06:58 - 00064624 _____ () C:\Users\Senel\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-27 06:50 - 2014-04-27 06:50 - 00300104 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-04-27 06:50 - 2014-04-27 06:50 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-27 05:15 - 2014-02-04 04:46 - 00000000 ____D () C:\Users\Senel\Desktop\Programme
2014-04-27 05:11 - 2014-04-27 05:09 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-27 05:11 - 2014-04-27 05:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-04-27 05:11 - 2014-04-27 05:09 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-27 05:09 - 2014-04-27 05:09 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Senel\Downloads\mbam-setup-2.0.0.1000.exe
2014-04-27 05:09 - 2014-04-27 05:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-27 05:07 - 2013-10-25 19:08 - 00000000 ____D () C:\Users\Senel\AppData\Roaming\TS3Client
2014-04-27 05:04 - 2012-12-23 02:00 - 00000000 ____D () C:\ProgramData\NexonEU
2014-04-27 04:50 - 2014-04-27 04:50 - 00001268 _____ () C:\Users\Senel\Desktop\Revo Uninstaller.lnk
2014-04-27 04:50 - 2014-04-27 04:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-27 04:49 - 2014-04-27 04:49 - 02617648 _____ (VS Revo Group Ltd.) C:\Users\Senel\Downloads\revosetup194.exe
2014-04-26 18:01 - 2014-02-04 03:04 - 00000000 ____D () C:\ProgramData\MFAData
2014-04-26 17:58 - 2011-12-29 20:31 - 00000000 ____D () C:\Users\Senel
2014-04-25 18:05 - 2014-04-25 18:04 - 00037888 _____ () C:\Users\Senel\Downloads\Addition.txt
2014-04-25 09:44 - 2014-04-01 08:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-04-25 09:44 - 2014-02-13 00:55 - 00000981 _____ () C:\Users\Public\Desktop\AVG 2014.lnk
2014-04-23 13:34 - 2013-01-03 14:18 - 00000000 ____D () C:\Users\Senel\Desktop\Kadir
2014-04-23 10:46 - 2012-01-04 20:27 - 00000000 ____D () C:\Users\Senel\AppData\Local\Sony
2014-04-23 10:42 - 2012-08-22 03:53 - 00000000 ____D () C:\Users\Senel\AppData\Local\Unity
2014-04-23 10:40 - 2014-04-22 20:10 - 00000000 ____D () C:\Program Files (x86)\GameforgeLive
2014-04-23 10:22 - 2014-03-04 12:54 - 00000000 ____D () C:\Users\Senel\AppData\Local\PMB Files
2014-04-23 10:22 - 2014-03-04 12:54 - 00000000 ____D () C:\ProgramData\PMB Files
2014-04-23 09:53 - 2014-04-23 09:49 - 00000000 ___HD () C:\Users\Senel\AppData\Local\Pvyjq
2014-04-22 00:09 - 2013-08-10 11:27 - 00000000 ____D () C:\Users\Administrator
2014-04-22 00:09 - 2013-08-04 15:25 - 00000000 ____D () C:\Users\Ridi
2014-04-18 15:01 - 2014-04-18 15:01 - 00237336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgidsdrivera.sys
2014-04-13 10:45 - 2014-04-13 10:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\AVG
2014-04-13 10:40 - 2014-04-13 10:40 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\AVG2014
2014-04-13 10:40 - 2014-04-13 10:40 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Avg2014
2014-04-12 15:33 - 2013-12-02 02:16 - 00000193 _____ () C:\Users\Senel\Videos\Documents\ads.txt
2014-04-11 09:33 - 2011-12-31 20:16 - 00004114 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-11 09:33 - 2011-12-31 20:16 - 00003862 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-10 21:18 - 2014-04-10 21:18 - 00000000 ____D () C:\Users\Senel\AppData\Local\dumps
2014-04-10 19:20 - 2014-04-10 19:20 - 00000178 _____ () C:\console.log
2014-04-10 18:43 - 2014-02-04 04:37 - 00003696 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-04-09 14:16 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-04-09 03:04 - 2012-10-03 14:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-09 03:03 - 2013-07-12 01:31 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-09 03:01 - 2011-12-29 20:51 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-07 19:09 - 2009-07-14 05:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-04 20:49 - 2013-08-05 15:20 - 00000089 _____ () C:\Users\Senel\Videos\Documents\.......txt
2014-04-03 09:51 - 2014-04-27 05:09 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-27 05:09 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-27 05:09 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-03 03:54 - 2012-01-04 20:26 - 00000000 ____D () C:\Users\Senel\AppData\Roaming\Sony
2014-04-01 11:30 - 2014-04-01 11:30 - 00000000 ____D () C:\Program Files\Sony
2014-04-01 11:30 - 2014-04-01 11:30 - 00000000 ____D () C:\Program Files (x86)\Sony
2014-03-31 16:20 - 2014-03-31 16:20 - 00274200 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgtdia.sys
2014-03-31 16:06 - 2014-03-31 16:06 - 00130840 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys
2014-03-31 03:16 - 2014-04-08 21:58 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-08 21:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-08 21:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-08 21:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-30 00:48 - 2013-08-04 15:26 - 00000000 ____D () C:\Users\Ridi\AppData\Local\VirtualStore
2014-03-30 00:15 - 2014-03-30 00:15 - 00000000 ____D () C:\Users\Ridi\AppData\Roaming\AVG
2014-03-30 00:10 - 2014-03-30 00:10 - 00000000 ____D () C:\Users\Ridi\AppData\Roaming\AVG2014
2014-03-30 00:10 - 2014-03-30 00:10 - 00000000 ____D () C:\Users\Ridi\AppData\Local\Avg2014
Files to move or delete:
====================
C:\ProgramData\libcurl.dll
C:\ProgramData\pthreadGC2.dll
C:\ProgramData\ras_0oed.pad
C:\ProgramData\zlib1.dll
Some content of TEMP:
====================
C:\Users\Senel\AppData\Local\Temp\NGM.exe
C:\Users\Senel\AppData\Local\Temp\NGMDll.dll
C:\Users\Senel\AppData\Local\Temp\NGMResource.dll
C:\Users\Senel\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-23 04:54
==================== End Of Log ============================ --- --- ---
--- --- --- |