TypMitHaaren | 06.05.2014 13:56 | Bei der deinstallation des Programmes ist ein Fehler aufgetreten...
Das heisst das ich es beireits durchgeführt habe und der **** immernoch da ist.. :(
JRM.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Niclas on 06.05.2014 at 14:30:38,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3192851615-808154685-2172071588-1001\Software\sweetim
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\systweak"
Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\advanced system protector"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.05.2014 at 14:34:40,97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ AdwCleanerS0: Code:
# AdwCleaner v3.205 - Bericht erstellt am 30/04/2014 um 16:15:01
# Aktualisiert 28/04/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Niclas - PURPLE-PC
# Gestartet von : D:\Users\Niclas\Downloads\adwcleaner-3.205.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : SystemStoreService
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\AVG Nation toolbar
Ordner Gelöscht : C:\Program Files (x86)\Delta
Ordner Gelöscht : C:\Program Files (x86)\Funmoods
Ordner Gelöscht : C:\Program Files (x86)\GreenTree Applications
Ordner Gelöscht : C:\Program Files (x86)\Industriya
Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater
Ordner Gelöscht : C:\Program Files (x86)\Common Files\AVG Secure Search
Ordner Gelöscht : C:\WINDOWS\SysWOW64\AI_RecycleBin
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\AVG Nation toolbar
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\DownloadGuide
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\FilesFrog Update Checker
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\webplayer
Ordner Gelöscht : C:\Users\Niclas\AppData\LocalLow\AVG Nation toolbar
Ordner Gelöscht : C:\Users\Niclas\AppData\LocalLow\GutscheinCodes
Ordner Gelöscht : C:\Users\Niclas\AppData\LocalLow\Industriya
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\DownLite
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\105p3hwn.default\Extensions\dc59fc10-5a26-4311-af8d-bf9b600a7b9c@080e29b9-9bee-4caa-b38c-4958c5aa2376.com
Datei Gelöscht : C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\105p3hwn.default\user.js
Datei Gelöscht : C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_deutsch.babylon.com_0.localstorage
Datei Gelöscht : C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_deutsch.babylon.com_0.localstorage-journal
Datei Gelöscht : C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.babylon.com_0.localstorage
Datei Gelöscht : C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_search.babylon.com_0.localstorage-journal
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Freemium1ClickMaint
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Software Updater
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player\Uninstall.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [FLV Player]
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SDP]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\GutscheinCodes.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\d
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaappCore.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltadskBnd.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\delta.deltaHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\esrv.deltaESrvc.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GutscheinCodes.GutscheinCodesBHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\GutscheinCodes.GutscheinCodesBHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\privitize.privitizeHlpr
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\privitize.privitizeHlpr.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Schlüssel Gelöscht : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Schlüssel Gelöscht : HKCU\Software\5e088d1e23ce442
Schlüssel Gelöscht : HKLM\SOFTWARE\5e088d1e23ce442
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052466.BHO
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052466.BHO.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052466.Sandbox
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CrossriderApp0052466.Sandbox.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{59279625-EFF0-4F55-98F0-51EDDD800DD9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1ACB5ABE-4890-4747-952C-F13BDB93FB75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{261DD098-8A3E-43D4-87AA-63324FA897D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4FCB4630-2A1C-4AA1-B422-345E8DC8A6DE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{86838207-681D-469D-9511-D0DCC6F19F9B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B25AEDC4-8086-41E3-8349-328223FA9FCB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E97A663B-81A6-49C5-A6D3-BCB05BA1DE26}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511241166}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522242266}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555245566}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566246666}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{39CB8175-E224-4446-8746-00566302DF8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4599D05A-D545-4069-BB42-5895B4EAE05B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{F905535E-9C87-4A3F-8A3E-4E3B54C461C5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{44444444-4444-4444-4444-440544244466}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ACB5ABE-4890-4747-952C-F13BDB93FB75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511241166}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1ACB5ABE-4890-4747-952C-F13BDB93FB75}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110511241166}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1ACB5ABE-4890-4747-952C-F13BDB93FB75}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{82E1477C-B154-48D3-9891-33D83C26BCD3}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C1AF5FA5-852C-4C90-812E-A7F75E011D87}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110511241166}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{348C2DF3-1191-4C3E-92A6-B3A89A9D9C85}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{C87FC351-A80D-43E9-9A86-CF1E29DC443A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{483830EE-A4CD-4B71-B0A3-3D82E62A6909}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{82E1477C-B154-48D3-9891-33D83C26BCD3}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A75BE48D-BF58-4A8B-B96C-F9A09DFB9844}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{11111111-1111-1111-1111-110511241166}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220522242266}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550555245566}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660566246666}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110511241166}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\AVG Nation toolbar
Schlüssel Gelöscht : HKCU\Software\BabSolution
Schlüssel Gelöscht : HKCU\Software\BI
Schlüssel Gelöscht : HKCU\Software\DataMngr
[#] Schlüssel Gelöscht : HKCU\Software\DataMngr_Toolbar
Schlüssel Gelöscht : HKCU\Software\Delta
Schlüssel Gelöscht : HKCU\Software\Funmoods
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\Somoto
Schlüssel Gelöscht : HKCU\Software\Webplayer
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\AVG Nation toolbar
Schlüssel Gelöscht : HKLM\Software\AVG Security Toolbar
Schlüssel Gelöscht : HKLM\Software\covus freemium gmbh
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Delta
Schlüssel Gelöscht : HKLM\Software\InstallCore
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Nation toolbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bi_uninstaller
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Delta
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FilesFrog Update Checker
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Funmoods
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16843
-\\ Mozilla Firefox v
[ Datei : C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\105p3hwn.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.adc59fc105a264311af8dbf9b600a7b9c080e29b99bee4caab38c4958c5aa2376com52466.52466.internaldb.Resources_meta.value", "%7B%22iframe.html%22%3A%7B%22id%22%3A538570%2C%22ver%22%3A18%2C[...]
Zeile gelöscht : user_pref("extensions.adc59fc105a264311af8dbf9b600a7b9c080e29b99bee4caab38c4958c5aa2376com52466.52466.internaldb.Resources_resource_538570.value", "%22%3Chtml%20style%3D%5C%22width%3A854px%3Bheigth%3A[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "144c2ec036c63cc4d15404d6c18e7e54");
-\\ Google Chrome v34.0.1847.131
[ Datei : C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Homepage] : hxxp://search.babylon.com/?babsrc=HP_ss&mntrId=56F8080027003CF0&affID=124589&tsp=5019
Gelöscht [Extension] : bbjciahceamgodcoidkjpchnokgfpphh
Gelöscht [Extension] : dhkplhfnhceodhffomolpfigojocbpcb
Gelöscht [Extension] : ndibdjnfmopecpmkdieinmbadjfpblof
*************************
AdwCleaner[R0].txt - [21323 octets] - [30/04/2014 16:13:51]
AdwCleaner[S0].txt - [19437 octets] - [30/04/2014 16:15:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19498 octets] ########## ...und S1: Code:
# AdwCleaner v3.205 - Bericht erstellt am 03/05/2014 um 18:08:09
# Aktualisiert 28/04/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Niclas - PURPLE-PC
# Gestartet von : D:\Users\Niclas\Downloads\adwcleaner-3.205.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : BackupStack
Dienst Gelöscht : LPTSystemUpdater
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Advanced System Protector
Ordner Gelöscht : C:\Program Files (x86)\LPT
Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\WINDOWS\Installer\{813BA625-B0FA-48D8-9B75-59759C88C219}
Ordner Gelöscht : C:\Users\Niclas\.android
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\LPT
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\Smartbar
Ordner Gelöscht : C:\Users\Niclas\AppData\Local\Temp\Smartbar
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Ordner Gelöscht : D:\Users\Niclas\Documents\Mobogenie
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\Users\Niclas\daemonprocess.txt
Datei Gelöscht : C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Datei Gelöscht : D:\Users\Niclas\Desktop\MyPC Backup.lnk
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Advanced System Protector
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : D:\Users\Niclas\Desktop\Search.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeMeter\Tools\CodeMeter Command Prompt.lnk
Verknüpfung Desinfiziert : C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Browser Infrastructure Helper]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bho
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MobogenieAdd
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [mobilegeni daemon]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10AD2C61-0898-4348-8600-14A342F22AC3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DCABB943-792E-44C4-9029-ECBEE6265AF9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10AD2C61-0898-4348-8600-14A342F22AC3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3408AC0D-510E-4808-8F7B-6B70B1F88534}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31AD400D-1B06-4E33-A59A-90C2C140CBA0}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\smartbarbackup
Schlüssel Gelöscht : HKCU\Software\smartbarlog
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Rr Savings
Schlüssel Gelöscht : HKLM\Software\AVG SafeGuard toolbar
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\LevelQualityWatcher
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Rr Savings
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{813BA625-B0FA-48D8-9B75-59759C88C219}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyPC Backup
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Features\526AB318AF0B8D84B9579557C9882C91
Schlüssel Gelöscht : HKLM\Software\Classes\Installer\Products\526AB318AF0B8D84B9579557C9882C91
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16843
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Bar]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [Default_Search_URL]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Search [SearchAssistant]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchUrl [Default]
-\\ Mozilla Firefox v
[ Datei : C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\105p3hwn.default\prefs.js ]
-\\ Google Chrome v34.0.1847.131
[ Datei : C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [21323 octets] - [30/04/2014 16:13:51]
AdwCleaner[R1].txt - [10892 octets] - [03/05/2014 18:06:33]
AdwCleaner[S0].txt - [19691 octets] - [30/04/2014 16:15:01]
AdwCleaner[S1].txt - [7714 octets] - [03/05/2014 18:08:09]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7774 octets] ########## (hab auch noch R0 und R1 fallsde die brauchst ;))
mbam.txt kommt gleich.
mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 06.05.2014
Suchlauf-Zeit: 14:49:09
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.06.04
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Niclas
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 279791
Verstrichene Zeit: 7 Min, 42 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 3
Adware.Adpeak, C:\Program Files\002\yewimmxqbs64.exe, 3628, Löschen bei Neustart, [98689a6637c914ec0d6ef23ccb39db25]
PUP.Optional.Adpeak.A, C:\Program Files\002\yewimmxqbs64.exe, 3628, Löschen bei Neustart, [5aa6c33de917d52b3607705190738878]
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\RrFilterService64.exe, 3440, Löschen bei Neustart, [619fcf31ca36f30d679cbbbaa45e07f9]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 15
Adware.Adpeak, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\yewimmxqbs64, In Quarantäne, [98689a6637c914ec0d6ef23ccb39db25],
PUP.Optional.Adpeak.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\yewimmxqbs64, In Quarantäne, [5aa6c33de917d52b3607705190738878],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\rrsavings, In Quarantäne, [a957ae52cc34639d664b6515c43e57a9],
PUP.Optional.PrivitizeTB.A, HKLM\SOFTWARE\CLASSES\esrv.privitizeESrvc, In Quarantäne, [ff0125db8779e51b39ed512d9c66df21],
PUP.Optional.PrivitizeTB.A, HKLM\SOFTWARE\CLASSES\esrv.privitizeESrvc.1, In Quarantäne, [b34d47b912ee728ea185b2ccb74bf30d],
PUP.Optional.RRSavings.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\rrsavings, In Quarantäne, [ce329967847c0cf42c835f1b55ad23dd],
PUP.Optional.PrivitizeTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.privitizeESrvc, In Quarantäne, [758b8b7524dc6e92bc6a83fb778bf60a],
PUP.Optional.PrivitizeTB.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.privitizeESrvc.1, In Quarantäne, [52aec8388c7451af52d4abd355ad7987],
PUP.Optional.PrivitizeTB.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dhfcbmlocifngpbjdpgnkbjmgkadkjpp, In Quarantäne, [c937956b5da387798f9bdba315edcc34],
PUP.Optional.PrivitizeTB.A, HKLM\SOFTWARE\WOW6432NODE\INDUSTRIYA\privitize, In Quarantäne, [7a86cd336c9416ea0324601e41c13ec2],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3192851615-808154685-2172071588-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\RrSavings, In Quarantäne, [728e5aa6a35d946cd6dd34468b77d22e],
PUP.Optional.FLVPlayerAddon.A, HKU\S-1-5-21-3192851615-808154685-2172071588-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\FLV Player Addon, In Quarantäne, [f10fb44c08f841bf2529e89c7f83ad53],
PUP.Optional.RRSavings.A, HKU\S-1-5-21-3192851615-808154685-2172071588-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\rrsavings, In Quarantäne, [bb45ee121ee241bfa70f0971bc46e917],
PUP.Optional.PrivitizeTB.A, HKU\S-1-5-21-3192851615-808154685-2172071588-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INDUSTRIYA\privitize, In Quarantäne, [f9072cd4e51b3fc161c7225c808219e7],
PUP.Optional.RRSavings.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\RrFilterService64, In Quarantäne, [619fcf31ca36f30d679cbbbaa45e07f9],
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 3
PUP.Optional.RRSavings.A, C:\Program Files\rrsavings, In Quarantäne, [b34dab55857b53ad818113625da56c94],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter, Löschen bei Neustart, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\SSL, In Quarantäne, [619fcf31ca36f30d679cbbbaa45e07f9],
Dateien: 19
Adware.Adpeak, C:\Program Files\002\yewimmxqbs64.exe, Löschen bei Neustart, [98689a6637c914ec0d6ef23ccb39db25],
PUP.Optional.OutBrowse, C:\Users\Niclas\AppData\Local\Temp\DownloadManager.exe, In Quarantäne, [78881de33fc18b75ce2644d95da3e61a],
PUP.Optional.Somoto.A, C:\Users\Niclas\Local Settings\Application Data\Bundled software uninstaller\biclient.exe, In Quarantäne, [cb352ed2dc24a9571f2c011445bc1be5],
PUP.Optional.PrivitizeTB.A, C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\105p3hwn.default\searchplugins\privitize.xml, In Quarantäne, [907017e935cba85860c4661855adf40c],
PUP.Optional.FLVPlayerAddon.A, C:\Windows\Tasks\FLV Player Addon-chromeinstaller.job, In Quarantäne, [0000ef1122deec14d07d7d07af53a35d],
PUP.Optional.FLVPlayerAddon.A, C:\Windows\Tasks\FLV Player Addon-codedownloader.job, In Quarantäne, [9769996741bfa45c133a5430c93903fd],
PUP.Optional.FLVPlayerAddon.A, C:\Windows\Tasks\FLV Player Addon-enabler.job, In Quarantäne, [0af606fa35cb748c7dd0156f6d9528d8],
PUP.Optional.FLVPlayerAddon.A, C:\Windows\Tasks\FLV Player Addon-firefoxinstaller.job, In Quarantäne, [e51bdc2478883dc3c9846a1a36ccf907],
PUP.Optional.Adpeak.A, C:\Program Files\002\yewimmxqbs64.exe, Löschen bei Neustart, [5aa6c33de917d52b3607705190738878],
PUP.Optional.FunMoods.A, C:\Users\Niclas\AppData\Local\funmoods_2.3.1.crx, In Quarantäne, [eb152bd56c94808016449829ed16c63a],
PUP.Optional.RRSavings.A, C:\Program Files\rrsavings\uninstaller.exe, In Quarantäne, [b34dab55857b53ad818113625da56c94],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Installbat64.dll, In Quarantäne, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Microsoft.Deployment.WindowsInstaller.dll, In Quarantäne, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\Microsoft.Deployment.WindowsInstaller.xml, In Quarantäne, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\nfapi.dll, Löschen bei Neustart, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\nfregdrv.exe, In Quarantäne, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\ProtocolFilters.dll, Löschen bei Neustart, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\RrFilterService64.exe, Löschen bei Neustart, [619fcf31ca36f30d679cbbbaa45e07f9],
PUP.Optional.RRSavings.A, C:\Program Files\RrFilter\sample.dll, In Quarantäne, [619fcf31ca36f30d679cbbbaa45e07f9],
Physische Sektoren: 0
(No malicious items detected)
(end) Alles in Quarantäne und die Addware ist augenscheinlich weg.
Abschliessender FRST Scan:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2014
Ran by Niclas (administrator) on PURPLE-PC on 06-05-2014 14:53:22
Running from D:\Users\Niclas\Downloads\FRST
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hi-Rez Studios) D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(Nero AG) D:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Windows\jmesoft\Service.exe
(Lenovo) C:\Program Files\Lenovo\Power Control Switch\LenovoCOMSvc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() D:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
() C:\Windows\SysWOW64\UMonit.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(Akamai Technologies, Inc.) C:\Users\Niclas\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Niclas\AppData\Local\Akamai\netsession_win.exe
(Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe
() D:\Program Files (x86)\puush\puush.exe
(Lenovo) C:\Windows\jmesoft\hotkey.exe
(LOL Replay) D:\Program Files (x86)\LOLReplay\LOLRecorder.exe
(Dropbox, Inc.) C:\Users\Niclas\AppData\Roaming\Dropbox\bin\Dropbox.exe
(GameRanger Technologies) C:\Users\Niclas\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
() C:\Windows\jmesoft\JME_LOAD.exe
(Lenovo) C:\Program Files\Lenovo\Power Control Switch\LitModeSwitch.exe
(Lenovo) C:\Program Files\Lenovo\Power Control Switch\LitModeCtrl.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Aeria Games & Entertainment) D:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Elaborate Bytes AG) D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
(Lenovo, Japan, Ltd. ) C:\Program Files (x86)\Lenovo\RapidDrive Advanced\LenovoRapidDriveAdvancedService.exe
() C:\Program Files (x86)\Lenovo\RapidDrive Advanced\LenovoRapidDriveAdvancedEvents.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12497552 2012-05-28] (Realtek Semiconductor)
HKLM\...\Run: [UMonit] => C:\WINDOWS\SysWOW64\UMonit.exe [28672 2012-07-24] ()
HKLM\...\Run: [ProfilerU] => C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] => C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM\...\Run: [Wippien] => D:\Program Files\Wippien\Wippien.exe [3022632 2011-08-19] ()
HKLM-x32\...\Run: [jmekey] => C:\WINDOWS\jmesoft\hotkey.exe [118784 2011-06-08] (Lenovo)
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-03-15] ()
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [ModeSwitch] => C:\Program Files\Lenovo\Power Control Switch\LitModeSwitch.exe [751104 2012-03-31] (Lenovo)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Aeria Ignite] => D:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5180432 2014-04-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [VirtualCloneDrive] => D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-04-15] (LogMeIn Inc.)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Niclas\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [uTorrent] => C:\Users\Niclas\AppData\Roaming\uTorrent\uTorrent.exe [902736 2013-10-28] (BitTorrent Inc.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [MoodEditor.exe] => D:\Program Files (x86)\Pamela RichMood Editor\MoodEditor.exe [1025024 2013-08-17] (Scendix Software-Vertriebsges. mbH)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [AVG-Secure-Search-Update_0913b] => C:\Users\Niclas\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 593f4c133c4647d39d03057438dc1a9f-753923bc94f738da406656e912a26fccb404e6d9 --CMPID 0913b
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Desura] => D:\Program Files (x86)\Desura\desura.exe [2529096 2014-01-05] (Desura Pty Ltd)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Skype] => D:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [puush] => D:\Program Files (x86)\puush\puush.exe [567880 2014-04-13] ()
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\MountPoints2: {068b5e74-fc89-11e2-bea4-d43d7e38f36c} - "H:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\MountPoints2: {29722606-ef7a-11e2-be8c-d43d7e38f36c} - "H:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\MountPoints2: {a43a989f-d8c8-11e2-be75-d43d7e38f36c} - "H:\HTC_Sync_Manager_PC.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
ShortcutTarget: LOLRecorder.lnk -> D:\Program Files (x86)\LOLReplay\LOLRecorder.exe (LOL Replay)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\phase-6 Reminder.lnk
ShortcutTarget: phase-6 Reminder.lnk -> D:\Program Files (x86)\phase-6\phase-6\reminder\reminder.exe (phase-6)
Startup: C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Niclas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk
ShortcutTarget: GameRanger.lnk -> C:\Users\Niclas\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)
==================== Internet (Whitelisted) ====================
ProxyServer: 80.87.240.49:8087
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM - DefaultScope {2E32E504-A3EA-4DB4-9876-2DCD2D89B98D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM - {2E32E504-A3EA-4DB4-9876-2DCD2D89B98D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095}
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\105p3hwn.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - D:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @exent.com/npExentControl,version=7.1.0.1 - C:\Program Files (x86)\FreeRide Games\npExentControl.dll No File
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - D:\Program Files (x86)\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - D:\Program Files (x86)\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nexon.net/NxGame - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npnxgameEU.dll (Nexon)
FF Plugin-x32: @ogplanet.com/npOGPPlugin - C:\WINDOWS\system32\npOGPPlugin.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Niclas\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF HKLM-x32\...\Firefox\Extensions: [fiddlerhook@fiddler2.com] - D:\Program Files (x86)\Fiddler2\FiddlerHook
FF Extension: FiddlerHook - D:\Program Files (x86)\Fiddler2\FiddlerHook [2014-01-18]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "sync_promo"
CHR StartupUrls: "startup_urls_migration_time": "13034373880206099"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll ()
CHR Plugin: (Exent® AOD Gecko Plugin) - C:\Program Files (x86)\FreeRide Games\npExentControl.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.16) - C:\WINDOWS\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - D:\Program Files (x86)\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-31]
CHR Extension: (Google Drive) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-31]
CHR Extension: (YouTube) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-31]
CHR Extension: (Battlefield Heroes) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-31]
CHR Extension: (Live HTTP Headers) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaiioopjkcekapmldfgbebdclcnpgnlo [2014-01-18]
CHR Extension: (Google Wallet) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Google Mail) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-31]
==================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3645456 2014-04-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [291912 2014-03-27] (AVG Technologies CZ, s.r.o.)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [484592 2013-11-15] (BitRaider, LLC)
R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2227536 2014-04-15] (LogMeIn Inc.)
U2 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios)
R2 HTCMonitorService; d:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-04-12] (Nero AG)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-15] ()
R3 Lenovo.RapidDrive.Advanced.Svc; C:\Program Files (x86)\Lenovo\RapidDrive Advanced\LenovoRapidDriveAdvancedService.exe [218112 2012-08-15] (Lenovo, Japan, Ltd. )
R2 LenovoCOMSvc; C:\Program Files\Lenovo\Power Control Switch\LenovoCOMSvc.exe [37888 2011-11-04] (Lenovo)
R3 LitModeCtrl; C:\Program Files\Lenovo\Power Control Switch\LitModeCtrl.exe [141824 2012-04-06] (Lenovo)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [4868640 2013-08-25] (INCA Internet Co., Ltd.)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2014-02-22] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S2 SkypeUpdate; D:\Program Files (x86)\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
S2 vToolbarUpdater18.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [237336 2014-04-18] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192792 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [236824 2014-03-27] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [324376 2014-03-27] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130840 2014-03-31] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [32536 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx64.sys [50464 2014-04-28] (AVG Technologies)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [274712 2014-03-31] (AVG Technologies CZ, s.r.o.)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2013-11-16] (BitRaider)
R3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [60928 2012-07-06] (GenesysLogic)
S3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2013-07-03] (LogMeIn Inc.)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-02-28] (NetFilterSDK.com)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 SaiMini; C:\Windows\System32\drivers\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
S3 sclbl; D:\AeriaGames\ScarletBlade\avital\scarbt64.sys [86352 2013-12-13] ()
S3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [106256 2013-04-12] (Oracle Corporation)
R3 wod0205; C:\Windows\system32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys [X]
S2 X5XSEx_Pr148; \??\C:\Program Files (x86)\FreeRide Games\X5XSEx_Pr148.Sys [X]
S3 X6va011; \??\C:\WINDOWS\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\WINDOWS\SysWOW64\Drivers\X6va012 [X]
S3 X6va013; \??\C:\WINDOWS\SysWOW64\Drivers\X6va013 [X]
S3 X6va014; \??\C:\WINDOWS\SysWOW64\Drivers\X6va014 [X]
S3 X6va015; \??\C:\WINDOWS\SysWOW64\Drivers\X6va015 [X]
S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-06 14:49 - 2014-05-06 14:49 - 00000000 ____H () C:\ProgramData\cm-lock
2014-05-06 14:39 - 2014-05-06 14:50 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-06 14:39 - 2014-05-06 14:39 - 00000787 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-06 14:39 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-05-06 14:39 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-05-06 14:39 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-05-06 14:30 - 2014-05-06 14:30 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-04 18:31 - 2014-05-04 18:31 - 00000000 ____D () C:\Users\Niclas\AppData\Local\InfiniteCrisis
2014-05-04 17:48 - 2014-05-04 17:48 - 00000000 ____D () C:\ProgramData\Turbine
2014-05-04 06:25 - 2014-05-04 06:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wizard101(DE)
2014-05-03 23:34 - 2014-05-03 23:34 - 00001070 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2014-05-03 23:33 - 2014-05-03 23:34 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\GameRanger
2014-05-03 20:29 - 2014-05-03 20:29 - 00000000 _____ () C:\Users\Niclas\defogger_reenable
2014-05-03 20:08 - 2014-05-06 14:53 - 00000000 ____D () C:\FRST
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\Rr Savings
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-05-03 18:02 - 2014-05-06 14:49 - 00000000 ____D () C:\Program Files\002
2014-05-03 18:02 - 2014-05-03 18:10 - 00001365 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-05-03 18:02 - 2014-05-03 18:02 - 00001212 _____ () C:\Users\Public\Desktop\Advanced System Protector.lnk
2014-05-03 18:02 - 2014-05-03 18:02 - 00000000 ____D () C:\Users\Niclas\AppData\Local\cache
2014-05-03 18:02 - 2012-07-25 12:03 - 00016896 _____ () C:\WINDOWS\system32\sasnative64.exe
2014-04-30 16:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-04-30 16:13 - 2014-05-03 18:08 - 00000000 ____D () C:\AdwCleaner
2014-04-28 15:22 - 2014-04-28 15:22 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-04-21 15:51 - 2014-04-21 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex-Editor MX
2014-04-18 15:01 - 2014-04-18 15:01 - 00237336 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2014-04-16 15:43 - 2014-04-16 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-04-15 08:29 - 2014-04-18 21:57 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Teeworlds
2014-04-13 23:39 - 2014-04-13 23:39 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\puush
2014-04-13 23:38 - 2014-04-13 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\TERA
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-04-10 23:30 - 2014-04-10 23:30 - 00000674 _____ () C:\Users\Public\Desktop\RFOnline1.0.lnk
2014-04-10 23:30 - 2014-04-10 23:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RFOnline1.0
2014-04-10 22:35 - 2014-04-10 22:35 - 00000358 _____ () C:\console.log
2014-04-10 22:35 - 2014-04-10 22:35 - 00000000 ____D () C:\Users\Niclas\RFO
2014-04-09 21:01 - 2014-04-09 21:01 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Carbon
2014-04-09 16:43 - 2014-04-09 17:39 - 00000000 ____D () C:\Users\Niclas\AppData\Local\UberLauncher
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SuperMNC
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Uber_Entertainment
2014-04-08 19:01 - 2014-04-09 12:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Dwarfs
2014-04-08 16:32 - 2014-04-08 16:32 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\SpringLobby
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spring
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spring
==================== One Month Modified Files and Folders =======
2014-05-06 14:53 - 2014-05-03 20:08 - 00000000 ____D () C:\FRST
2014-05-06 14:51 - 2013-08-25 19:11 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Skype
2014-05-06 14:50 - 2014-05-06 14:39 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-06 14:50 - 2013-09-14 14:54 - 00000000 ____D () C:\Users\Niclas\AppData\Local\LogMeIn Hamachi
2014-05-06 14:50 - 2013-08-04 10:43 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Dropbox
2014-05-06 14:50 - 2013-06-20 18:53 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-05-06 14:49 - 2014-05-06 14:49 - 00000000 ____H () C:\ProgramData\cm-lock
2014-05-06 14:49 - 2014-05-03 18:02 - 00000000 ____D () C:\Program Files\002
2014-05-06 14:49 - 2013-08-31 21:31 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-06 14:49 - 2013-08-03 22:49 - 00000000 ____D () C:\Users\Niclas\AppData\Local\HTC MediaHub
2014-05-06 14:49 - 2012-08-01 17:51 - 00038286 _____ () C:\WINDOWS\PFRO.log
2014-05-06 14:49 - 2012-07-26 09:22 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-06 14:49 - 2012-07-26 07:26 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-05-06 14:47 - 2013-06-21 18:41 - 00003938 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5658A565-CBA7-45CE-A1A3-2BE0A5C61F68}
2014-05-06 14:39 - 2014-05-06 14:39 - 00000787 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-06 14:37 - 2013-06-17 17:01 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3192851615-808154685-2172071588-1001
2014-05-06 14:30 - 2014-05-06 14:30 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-06 14:27 - 2013-08-21 10:31 - 00000000 ____D () C:\ProgramData\MFAData
2014-05-06 14:26 - 2013-01-08 16:54 - 00761898 _____ () C:\WINDOWS\system32\perfh007.dat
2014-05-06 14:26 - 2013-01-08 16:54 - 00160028 _____ () C:\WINDOWS\system32\perfc007.dat
2014-05-06 14:26 - 2012-07-26 09:28 - 01772590 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-05 21:02 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-05-05 20:56 - 2013-08-31 21:31 - 00001130 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-04 21:17 - 2013-06-17 19:25 - 00000000 ____D () C:\Users\Niclas\AppData\Local\PMB Files
2014-05-04 18:31 - 2014-05-04 18:31 - 00000000 ____D () C:\Users\Niclas\AppData\Local\InfiniteCrisis
2014-05-04 17:51 - 2013-08-11 09:21 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Turbine
2014-05-04 17:50 - 2013-12-02 10:46 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Adobe
2014-05-04 17:49 - 2013-06-20 12:35 - 00253987 _____ () C:\WINDOWS\DirectX.log
2014-05-04 17:48 - 2014-05-04 17:48 - 00000000 ____D () C:\ProgramData\Turbine
2014-05-04 17:47 - 2013-06-17 19:25 - 00000000 ____D () C:\ProgramData\PMB Files
2014-05-04 09:33 - 2012-07-26 07:26 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-05-04 06:25 - 2014-05-04 06:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wizard101(DE)
2014-05-04 05:53 - 2013-06-20 14:53 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\.minecraft
2014-05-04 00:57 - 2013-01-08 08:04 - 00000000 ____D () C:\Program Files (x86)\SugarSync
2014-05-03 23:34 - 2014-05-03 23:34 - 00001070 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2014-05-03 23:34 - 2014-05-03 23:33 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\GameRanger
2014-05-03 23:34 - 2013-06-17 16:54 - 00000000 ___RD () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-03 21:04 - 2013-06-19 16:03 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Akamai
2014-05-03 20:29 - 2014-05-03 20:29 - 00000000 _____ () C:\Users\Niclas\defogger_reenable
2014-05-03 20:29 - 2013-06-17 16:53 - 00000000 ____D () C:\Users\Niclas
2014-05-03 18:10 - 2014-05-03 18:02 - 00001365 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-05-03 18:08 - 2014-04-30 16:13 - 00000000 ____D () C:\AdwCleaner
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\Rr Savings
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-05-03 18:02 - 2014-05-03 18:02 - 00001212 _____ () C:\Users\Public\Desktop\Advanced System Protector.lnk
2014-05-03 18:02 - 2014-05-03 18:02 - 00000000 ____D () C:\Users\Niclas\AppData\Local\cache
2014-05-03 14:08 - 2013-09-04 19:22 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Paint.NET
2014-04-30 16:15 - 2014-03-10 20:20 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player
2014-04-28 19:50 - 2013-06-20 18:53 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-04-28 15:22 - 2014-04-28 15:22 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-04-28 15:22 - 2013-09-28 15:53 - 00050464 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys
2014-04-27 10:57 - 2013-08-31 21:32 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-25 11:35 - 2014-03-31 15:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-04-25 11:15 - 2013-06-22 12:02 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\TS3Client
2014-04-22 15:57 - 2013-01-08 08:04 - 00000000 ____D () C:\ProgramData\CyberLink
2014-04-21 15:51 - 2014-04-21 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex-Editor MX
2014-04-18 21:57 - 2014-04-15 08:29 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Teeworlds
2014-04-18 15:01 - 2014-04-18 15:01 - 00237336 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2014-04-16 15:43 - 2014-04-16 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-04-14 09:18 - 2013-07-19 22:34 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Deployment
2014-04-13 23:39 - 2014-04-13 23:39 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\puush
2014-04-13 23:38 - 2014-04-13 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\TERA
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-04-10 23:30 - 2014-04-10 23:30 - 00000674 _____ () C:\Users\Public\Desktop\RFOnline1.0.lnk
2014-04-10 23:30 - 2014-04-10 23:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RFOnline1.0
2014-04-10 22:35 - 2014-04-10 22:35 - 00000358 _____ () C:\console.log
2014-04-10 22:35 - 2014-04-10 22:35 - 00000000 ____D () C:\Users\Niclas\RFO
2014-04-09 21:01 - 2014-04-09 21:01 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Carbon
2014-04-09 20:59 - 2013-06-19 18:52 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Awesomium
2014-04-09 17:39 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Local\UberLauncher
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SuperMNC
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Uber_Entertainment
2014-04-09 12:25 - 2014-04-08 19:01 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Dwarfs
2014-04-08 18:57 - 2013-07-24 11:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-04-08 16:32 - 2014-04-08 16:32 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\SpringLobby
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spring
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spring
2014-04-08 15:28 - 2014-01-20 16:41 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\HpUpdate
Files to move or delete:
====================
C:\ProgramData\hash.dat
Some content of TEMP:
====================
C:\Users\Niclas\AppData\Local\Temp\032939rr.exe
C:\Users\Niclas\AppData\Local\Temp\6_Offer_12.exe
C:\Users\Niclas\AppData\Local\Temp\BackupSetup.exe
C:\Users\Niclas\AppData\Local\Temp\bdfilters.dll
C:\Users\Niclas\AppData\Local\Temp\borlndlm.dll
C:\Users\Niclas\AppData\Local\Temp\drm_dyndata_7380014.dll
C:\Users\Niclas\AppData\Local\Temp\HiPatchSelfUpdateWindow.exe
C:\Users\Niclas\AppData\Local\Temp\HiRezLauncherControls.dll
C:\Users\Niclas\AppData\Local\Temp\i4jdel0.exe
C:\Users\Niclas\AppData\Local\Temp\jansi-32-git-Bukkit-1.5.2-R0.1-b2771jnks.dll
C:\Users\Niclas\AppData\Local\Temp\jansi-64-git-Bukkit-1.5.2-R0.1-b2771jnks.dll
C:\Users\Niclas\AppData\Local\Temp\NGMDll.dll
C:\Users\Niclas\AppData\Local\Temp\NGMResource.dll
C:\Users\Niclas\AppData\Local\Temp\NGMSetup.exe
C:\Users\Niclas\AppData\Local\Temp\Quarantine.exe
C:\Users\Niclas\AppData\Local\Temp\rad5D9E3.tmp_update.exe
C:\Users\Niclas\AppData\Local\Temp\ubertmp.exe
C:\Users\Niclas\AppData\Local\Temp\unicows.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-27 12:07
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Addition (falls überhaupt noch nötig ;))
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2014
Ran by Niclas (administrator) on PURPLE-PC on 06-05-2014 14:53:22
Running from D:\Users\Niclas\Downloads\FRST
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hi-Rez Studios) D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe
(Nero AG) D:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
() C:\Windows\jmesoft\Service.exe
(Lenovo) C:\Program Files\Lenovo\Power Control Switch\LenovoCOMSvc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() D:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(LogMeIn Inc.) D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
() C:\Windows\SysWOW64\UMonit.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(LogMeIn, Inc.) D:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Saitek) C:\Program Files\SmartTechnology\Software\ProfilerU.exe
(Saitek) C:\Program Files\SmartTechnology\Software\SaiMfd.exe
(Akamai Technologies, Inc.) C:\Users\Niclas\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Niclas\AppData\Local\Akamai\netsession_win.exe
(Valve Corporation) D:\Program Files (x86)\Steam\Steam.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe
(Skype Technologies S.A.) D:\Program Files (x86)\Skype\Phone\Skype.exe
() D:\Program Files (x86)\puush\puush.exe
(Lenovo) C:\Windows\jmesoft\hotkey.exe
(LOL Replay) D:\Program Files (x86)\LOLReplay\LOLRecorder.exe
(Dropbox, Inc.) C:\Users\Niclas\AppData\Roaming\Dropbox\bin\Dropbox.exe
(GameRanger Technologies) C:\Users\Niclas\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
() C:\Windows\jmesoft\JME_LOAD.exe
(Lenovo) C:\Program Files\Lenovo\Power Control Switch\LitModeSwitch.exe
(Lenovo) C:\Program Files\Lenovo\Power Control Switch\LitModeCtrl.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Aeria Games & Entertainment) D:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe
(Elaborate Bytes AG) D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet Pro 8600\Bin\HPNetworkCommunicator.exe
(Lenovo, Japan, Ltd. ) C:\Program Files (x86)\Lenovo\RapidDrive Advanced\LenovoRapidDriveAdvancedService.exe
() C:\Program Files (x86)\Lenovo\RapidDrive Advanced\LenovoRapidDriveAdvancedEvents.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12497552 2012-05-28] (Realtek Semiconductor)
HKLM\...\Run: [UMonit] => C:\WINDOWS\SysWOW64\UMonit.exe [28672 2012-07-24] ()
HKLM\...\Run: [ProfilerU] => C:\Program Files\SmartTechnology\Software\ProfilerU.exe [454144 2013-04-16] (Saitek)
HKLM\...\Run: [SaiMfd] => C:\Program Files\SmartTechnology\Software\SaiMfd.exe [158208 2013-04-16] (Saitek)
HKLM\...\Run: [Wippien] => D:\Program Files\Wippien\Wippien.exe [3022632 2011-08-19] ()
HKLM-x32\...\Run: [jmekey] => C:\WINDOWS\jmesoft\hotkey.exe [118784 2011-06-08] (Lenovo)
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-03-15] ()
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [ModeSwitch] => C:\Program Files\Lenovo\Power Control Switch\LitModeSwitch.exe [751104 2012-03-31] (Lenovo)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Aeria Ignite] => D:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5180432 2014-04-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [VirtualCloneDrive] => D:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-04-15] (LogMeIn Inc.)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Niclas\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [uTorrent] => C:\Users\Niclas\AppData\Roaming\uTorrent\uTorrent.exe [902736 2013-10-28] (BitTorrent Inc.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\Steam.exe [1825984 2014-04-24] (Valve Corporation)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [MoodEditor.exe] => D:\Program Files (x86)\Pamela RichMood Editor\MoodEditor.exe [1025024 2013-08-17] (Scendix Software-Vertriebsges. mbH)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [AVG-Secure-Search-Update_0913b] => C:\Users\Niclas\AppData\Roaming\AVG 0913b Campaign\AVG-Secure-Search-Update-0913b.exe /PROMPT --mid 593f4c133c4647d39d03057438dc1a9f-753923bc94f738da406656e912a26fccb404e6d9 --CMPID 0913b
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Desura] => D:\Program Files (x86)\Desura\desura.exe [2529096 2014-01-05] (Desura Pty Ltd)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [HP Officejet Pro 8600 (NET)] => C:\Program Files\HP\HP Officejet Pro 8600\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [Skype] => D:\Program Files (x86)\Skype\Phone\Skype.exe [20922016 2014-02-10] (Skype Technologies S.A.)
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\Run: [puush] => D:\Program Files (x86)\puush\puush.exe [567880 2014-04-13] ()
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\MountPoints2: {068b5e74-fc89-11e2-bea4-d43d7e38f36c} - "H:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\MountPoints2: {29722606-ef7a-11e2-be8c-d43d7e38f36c} - "H:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-3192851615-808154685-2172071588-1001\...\MountPoints2: {a43a989f-d8c8-11e2-be75-d43d7e38f36c} - "H:\HTC_Sync_Manager_PC.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\LOLRecorder.lnk
ShortcutTarget: LOLRecorder.lnk -> D:\Program Files (x86)\LOLReplay\LOLRecorder.exe (LOL Replay)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\phase-6 Reminder.lnk
ShortcutTarget: phase-6 Reminder.lnk -> D:\Program Files (x86)\phase-6\phase-6\reminder\reminder.exe (phase-6)
Startup: C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Niclas\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameRanger.lnk
ShortcutTarget: GameRanger.lnk -> C:\Users\Niclas\AppData\Roaming\GameRanger\GameRanger\GameRanger.exe (GameRanger Technologies)
==================== Internet (Whitelisted) ====================
ProxyServer: 80.87.240.49:8087
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKLM - DefaultScope {2E32E504-A3EA-4DB4-9876-2DCD2D89B98D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
SearchScopes: HKLM - {2E32E504-A3EA-4DB4-9876-2DCD2D89B98D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MALNJS
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files (x86)\Java\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files (x86)\Java\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {4FF78044-96B4-4312-A5B7-FDA3CB328095}
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Niclas\AppData\Roaming\Mozilla\Firefox\Profiles\105p3hwn.default
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @java.com/DTPlugin,version=10.45.2 - D:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.45.2 - D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @exent.com/npExentControl,version=7.1.0.1 - C:\Program Files (x86)\FreeRide Games\npExentControl.dll No File
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - D:\Program Files (x86)\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - D:\Program Files (x86)\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @nexon.net/NxGame - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF Plugin-x32: @ngm.nexoneu.com/NxGame - C:\ProgramData\NexonEU\NGM\npnxgameEU.dll (Nexon)
FF Plugin-x32: @ogplanet.com/npOGPPlugin - C:\WINDOWS\system32\npOGPPlugin.dll No File
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Niclas\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF HKLM-x32\...\Firefox\Extensions: [fiddlerhook@fiddler2.com] - D:\Program Files (x86)\Fiddler2\FiddlerHook
FF Extension: FiddlerHook - D:\Program Files (x86)\Fiddler2\FiddlerHook [2014-01-18]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR HomePage: hxxp://www.google.com/
CHR RestoreOnStartup: "sync_promo"
CHR StartupUrls: "startup_urls_migration_time": "13034373880206099"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.131\pdf.dll ()
CHR Plugin: (Exent® AOD Gecko Plugin) - C:\Program Files (x86)\FreeRide Games\npExentControl.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll No File
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel® Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.250.16) - C:\WINDOWS\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U25) - D:\Program Files (x86)\Java\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Extension: (Google Docs) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-31]
CHR Extension: (Google Drive) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-31]
CHR Extension: (YouTube) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-31]
CHR Extension: (Battlefield Heroes) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2014-02-22]
CHR Extension: (Google-Suche) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-31]
CHR Extension: (Live HTTP Headers) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaiioopjkcekapmldfgbebdclcnpgnlo [2014-01-18]
CHR Extension: (Google Wallet) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-31]
CHR Extension: (Google Mail) - C:\Users\Niclas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-31]
==================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3645456 2014-04-18] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [291912 2014-03-27] (AVG Technologies CZ, s.r.o.)
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [484592 2013-11-15] (BitRaider, LLC)
R2 Hamachi2Svc; D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2227536 2014-04-15] (LogMeIn Inc.)
U2 HiPatchService; D:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-02-28] (Hi-Rez Studios)
R2 HTCMonitorService; d:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-04-12] (Nero AG)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-03-15] ()
R3 Lenovo.RapidDrive.Advanced.Svc; C:\Program Files (x86)\Lenovo\RapidDrive Advanced\LenovoRapidDriveAdvancedService.exe [218112 2012-08-15] (Lenovo, Japan, Ltd. )
R2 LenovoCOMSvc; C:\Program Files\Lenovo\Power Control Switch\LenovoCOMSvc.exe [37888 2011-11-04] (Lenovo)
R3 LitModeCtrl; C:\Program Files\Lenovo\Power Control Switch\LitModeCtrl.exe [141824 2012-04-06] (Lenovo)
S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [4868640 2013-08-25] (INCA Internet Co., Ltd.)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2014-02-22] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [118520 2013-03-01] (Riverbed Technology, Inc.)
S2 SkypeUpdate; D:\Program Files (x86)\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-10-25] (Microsoft Corporation)
S2 vToolbarUpdater18.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\18.1.0\ToolbarUpdater.exe [X]
==================== Drivers (Whitelisted) ====================
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [237336 2014-04-18] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [192792 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [236824 2014-03-27] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [324376 2014-03-27] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [130840 2014-03-31] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [32536 2014-03-27] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\WINDOWS\system32\drivers\avgtpx64.sys [50464 2014-04-28] (AVG Technologies)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [274712 2014-03-31] (AVG Technologies CZ, s.r.o.)
S3 BRDriver64; C:\ProgramData\BitRaider\BRDriver64.sys [75048 2013-11-16] (BitRaider)
R3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [60928 2012-07-06] (GenesysLogic)
S3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [46136 2013-07-03] (LogMeIn Inc.)
R1 netfilter64; C:\Windows\System32\drivers\netfilter64.sys [46376 2014-02-28] (NetFilterSDK.com)
R2 NPF; C:\Windows\System32\drivers\npf.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 SaiMini; C:\Windows\System32\drivers\SaiMini.sys [25120 2013-04-30] (Saitek)
R3 SaiNtBus; C:\Windows\system32\drivers\SaiBus.sys [52640 2013-04-30] (Saitek)
S3 sclbl; D:\AeriaGames\ScarletBlade\avital\scarbt64.sys [86352 2013-12-13] ()
S3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 VBoxUSB; C:\Windows\System32\Drivers\VBoxUSB.sys [106256 2013-04-12] (Oracle Corporation)
R3 wod0205; C:\Windows\system32\DRIVERS\wod0205.sys [33160 2011-04-23] (WeOnlyDo Software)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
S3 EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys [X]
S2 X5XSEx_Pr148; \??\C:\Program Files (x86)\FreeRide Games\X5XSEx_Pr148.Sys [X]
S3 X6va011; \??\C:\WINDOWS\SysWOW64\Drivers\X6va011 [X]
S3 X6va012; \??\C:\WINDOWS\SysWOW64\Drivers\X6va012 [X]
S3 X6va013; \??\C:\WINDOWS\SysWOW64\Drivers\X6va013 [X]
S3 X6va014; \??\C:\WINDOWS\SysWOW64\Drivers\X6va014 [X]
S3 X6va015; \??\C:\WINDOWS\SysWOW64\Drivers\X6va015 [X]
S3 xhunter1; \??\C:\WINDOWS\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-06 14:49 - 2014-05-06 14:49 - 00000000 ____H () C:\ProgramData\cm-lock
2014-05-06 14:39 - 2014-05-06 14:50 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-06 14:39 - 2014-05-06 14:39 - 00000787 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-06 14:39 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-05-06 14:39 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-05-06 14:39 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-05-06 14:30 - 2014-05-06 14:30 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-04 18:31 - 2014-05-04 18:31 - 00000000 ____D () C:\Users\Niclas\AppData\Local\InfiniteCrisis
2014-05-04 17:48 - 2014-05-04 17:48 - 00000000 ____D () C:\ProgramData\Turbine
2014-05-04 06:25 - 2014-05-04 06:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wizard101(DE)
2014-05-03 23:34 - 2014-05-03 23:34 - 00001070 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2014-05-03 23:33 - 2014-05-03 23:34 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\GameRanger
2014-05-03 20:29 - 2014-05-03 20:29 - 00000000 _____ () C:\Users\Niclas\defogger_reenable
2014-05-03 20:08 - 2014-05-06 14:53 - 00000000 ____D () C:\FRST
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\Rr Savings
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-05-03 18:02 - 2014-05-06 14:49 - 00000000 ____D () C:\Program Files\002
2014-05-03 18:02 - 2014-05-03 18:10 - 00001365 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-05-03 18:02 - 2014-05-03 18:02 - 00001212 _____ () C:\Users\Public\Desktop\Advanced System Protector.lnk
2014-05-03 18:02 - 2014-05-03 18:02 - 00000000 ____D () C:\Users\Niclas\AppData\Local\cache
2014-05-03 18:02 - 2012-07-25 12:03 - 00016896 _____ () C:\WINDOWS\system32\sasnative64.exe
2014-04-30 16:14 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-04-30 16:13 - 2014-05-03 18:08 - 00000000 ____D () C:\AdwCleaner
2014-04-28 15:22 - 2014-04-28 15:22 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-04-21 15:51 - 2014-04-21 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex-Editor MX
2014-04-18 15:01 - 2014-04-18 15:01 - 00237336 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2014-04-16 15:43 - 2014-04-16 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-04-15 08:29 - 2014-04-18 21:57 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Teeworlds
2014-04-13 23:39 - 2014-04-13 23:39 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\puush
2014-04-13 23:38 - 2014-04-13 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\TERA
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-04-10 23:30 - 2014-04-10 23:30 - 00000674 _____ () C:\Users\Public\Desktop\RFOnline1.0.lnk
2014-04-10 23:30 - 2014-04-10 23:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RFOnline1.0
2014-04-10 22:35 - 2014-04-10 22:35 - 00000358 _____ () C:\console.log
2014-04-10 22:35 - 2014-04-10 22:35 - 00000000 ____D () C:\Users\Niclas\RFO
2014-04-09 21:01 - 2014-04-09 21:01 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Carbon
2014-04-09 16:43 - 2014-04-09 17:39 - 00000000 ____D () C:\Users\Niclas\AppData\Local\UberLauncher
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SuperMNC
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Uber_Entertainment
2014-04-08 19:01 - 2014-04-09 12:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Dwarfs
2014-04-08 16:32 - 2014-04-08 16:32 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\SpringLobby
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spring
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spring
==================== One Month Modified Files and Folders =======
2014-05-06 14:53 - 2014-05-03 20:08 - 00000000 ____D () C:\FRST
2014-05-06 14:51 - 2013-08-25 19:11 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Skype
2014-05-06 14:50 - 2014-05-06 14:39 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-06 14:50 - 2013-09-14 14:54 - 00000000 ____D () C:\Users\Niclas\AppData\Local\LogMeIn Hamachi
2014-05-06 14:50 - 2013-08-04 10:43 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Dropbox
2014-05-06 14:50 - 2013-06-20 18:53 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-05-06 14:49 - 2014-05-06 14:49 - 00000000 ____H () C:\ProgramData\cm-lock
2014-05-06 14:49 - 2014-05-03 18:02 - 00000000 ____D () C:\Program Files\002
2014-05-06 14:49 - 2013-08-31 21:31 - 00001126 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-05-06 14:49 - 2013-08-03 22:49 - 00000000 ____D () C:\Users\Niclas\AppData\Local\HTC MediaHub
2014-05-06 14:49 - 2012-08-01 17:51 - 00038286 _____ () C:\WINDOWS\PFRO.log
2014-05-06 14:49 - 2012-07-26 09:22 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-06 14:49 - 2012-07-26 07:26 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-05-06 14:47 - 2013-06-21 18:41 - 00003938 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5658A565-CBA7-45CE-A1A3-2BE0A5C61F68}
2014-05-06 14:39 - 2014-05-06 14:39 - 00000787 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-06 14:39 - 2014-05-06 14:39 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-06 14:37 - 2013-06-17 17:01 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3192851615-808154685-2172071588-1001
2014-05-06 14:30 - 2014-05-06 14:30 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-06 14:27 - 2013-08-21 10:31 - 00000000 ____D () C:\ProgramData\MFAData
2014-05-06 14:26 - 2013-01-08 16:54 - 00761898 _____ () C:\WINDOWS\system32\perfh007.dat
2014-05-06 14:26 - 2013-01-08 16:54 - 00160028 _____ () C:\WINDOWS\system32\perfc007.dat
2014-05-06 14:26 - 2012-07-26 09:28 - 01772590 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-05 21:02 - 2012-07-26 10:12 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-05-05 20:56 - 2013-08-31 21:31 - 00001130 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-05-04 21:17 - 2013-06-17 19:25 - 00000000 ____D () C:\Users\Niclas\AppData\Local\PMB Files
2014-05-04 18:31 - 2014-05-04 18:31 - 00000000 ____D () C:\Users\Niclas\AppData\Local\InfiniteCrisis
2014-05-04 17:51 - 2013-08-11 09:21 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Turbine
2014-05-04 17:50 - 2013-12-02 10:46 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Adobe
2014-05-04 17:49 - 2013-06-20 12:35 - 00253987 _____ () C:\WINDOWS\DirectX.log
2014-05-04 17:48 - 2014-05-04 17:48 - 00000000 ____D () C:\ProgramData\Turbine
2014-05-04 17:47 - 2013-06-17 19:25 - 00000000 ____D () C:\ProgramData\PMB Files
2014-05-04 09:33 - 2012-07-26 07:26 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-05-04 06:25 - 2014-05-04 06:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wizard101(DE)
2014-05-04 05:53 - 2013-06-20 14:53 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\.minecraft
2014-05-04 00:57 - 2013-01-08 08:04 - 00000000 ____D () C:\Program Files (x86)\SugarSync
2014-05-03 23:34 - 2014-05-03 23:34 - 00001070 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2014-05-03 23:34 - 2014-05-03 23:33 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\GameRanger
2014-05-03 23:34 - 2013-06-17 16:54 - 00000000 ___RD () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-03 21:04 - 2013-06-19 16:03 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Akamai
2014-05-03 20:29 - 2014-05-03 20:29 - 00000000 _____ () C:\Users\Niclas\defogger_reenable
2014-05-03 20:29 - 2013-06-17 16:53 - 00000000 ____D () C:\Users\Niclas
2014-05-03 18:10 - 2014-05-03 18:02 - 00001365 _____ () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-05-03 18:08 - 2014-04-30 16:13 - 00000000 ____D () C:\AdwCleaner
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\Rr Savings
2014-05-03 18:03 - 2014-05-03 18:03 - 00000000 ____D () C:\Program Files (x86)\7-Zip
2014-05-03 18:02 - 2014-05-03 18:02 - 00001212 _____ () C:\Users\Public\Desktop\Advanced System Protector.lnk
2014-05-03 18:02 - 2014-05-03 18:02 - 00000000 ____D () C:\Users\Niclas\AppData\Local\cache
2014-05-03 14:08 - 2013-09-04 19:22 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Paint.NET
2014-04-30 16:15 - 2014-03-10 20:20 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FLV Player
2014-04-28 19:50 - 2013-06-20 18:53 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-04-28 15:22 - 2014-04-28 15:22 - 00000000 ____D () C:\ProgramData\AVG Secure Search
2014-04-28 15:22 - 2013-09-28 15:53 - 00050464 _____ (AVG Technologies) C:\WINDOWS\system32\Drivers\avgtpx64.sys
2014-04-27 10:57 - 2013-08-31 21:32 - 00002186 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-25 11:35 - 2014-03-31 15:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-04-25 11:15 - 2013-06-22 12:02 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\TS3Client
2014-04-22 15:57 - 2013-01-08 08:04 - 00000000 ____D () C:\ProgramData\CyberLink
2014-04-21 15:51 - 2014-04-21 15:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hex-Editor MX
2014-04-18 21:57 - 2014-04-15 08:29 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Teeworlds
2014-04-18 15:01 - 2014-04-18 15:01 - 00237336 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgidsdrivera.sys
2014-04-16 15:43 - 2014-04-16 15:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2014-04-14 09:18 - 2013-07-19 22:34 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Deployment
2014-04-13 23:39 - 2014-04-13 23:39 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\puush
2014-04-13 23:38 - 2014-04-13 23:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\puush
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\TERA
2014-04-12 00:09 - 2014-04-12 00:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TERA
2014-04-10 23:30 - 2014-04-10 23:30 - 00000674 _____ () C:\Users\Public\Desktop\RFOnline1.0.lnk
2014-04-10 23:30 - 2014-04-10 23:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RFOnline1.0
2014-04-10 22:35 - 2014-04-10 22:35 - 00000358 _____ () C:\console.log
2014-04-10 22:35 - 2014-04-10 22:35 - 00000000 ____D () C:\Users\Niclas\RFO
2014-04-09 21:01 - 2014-04-09 21:01 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Carbon
2014-04-09 20:59 - 2013-06-19 18:52 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Awesomium
2014-04-09 17:39 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Local\UberLauncher
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SuperMNC
2014-04-09 16:43 - 2014-04-09 16:43 - 00000000 ____D () C:\Users\Niclas\AppData\Local\Uber_Entertainment
2014-04-09 12:25 - 2014-04-08 19:01 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Dwarfs
2014-04-08 18:57 - 2013-07-24 11:25 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-04-08 16:32 - 2014-04-08 16:32 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\SpringLobby
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spring
2014-04-08 16:29 - 2014-04-08 16:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spring
2014-04-08 15:28 - 2014-01-20 16:41 - 00000000 ____D () C:\Users\Niclas\AppData\Roaming\HpUpdate
Files to move or delete:
====================
C:\ProgramData\hash.dat
Some content of TEMP:
====================
C:\Users\Niclas\AppData\Local\Temp\032939rr.exe
C:\Users\Niclas\AppData\Local\Temp\6_Offer_12.exe
C:\Users\Niclas\AppData\Local\Temp\BackupSetup.exe
C:\Users\Niclas\AppData\Local\Temp\bdfilters.dll
C:\Users\Niclas\AppData\Local\Temp\borlndlm.dll
C:\Users\Niclas\AppData\Local\Temp\drm_dyndata_7380014.dll
C:\Users\Niclas\AppData\Local\Temp\HiPatchSelfUpdateWindow.exe
C:\Users\Niclas\AppData\Local\Temp\HiRezLauncherControls.dll
C:\Users\Niclas\AppData\Local\Temp\i4jdel0.exe
C:\Users\Niclas\AppData\Local\Temp\jansi-32-git-Bukkit-1.5.2-R0.1-b2771jnks.dll
C:\Users\Niclas\AppData\Local\Temp\jansi-64-git-Bukkit-1.5.2-R0.1-b2771jnks.dll
C:\Users\Niclas\AppData\Local\Temp\NGMDll.dll
C:\Users\Niclas\AppData\Local\Temp\NGMResource.dll
C:\Users\Niclas\AppData\Local\Temp\NGMSetup.exe
C:\Users\Niclas\AppData\Local\Temp\Quarantine.exe
C:\Users\Niclas\AppData\Local\Temp\rad5D9E3.tmp_update.exe
C:\Users\Niclas\AppData\Local\Temp\ubertmp.exe
C:\Users\Niclas\AppData\Local\Temp\unicows.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-27 12:07
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Soviel "FRST Log"..... |