noknow85 | 10.05.2014 13:31 | Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 10-05-2014
Ran by freezon at 2014-05-10 13:19:08 Run:1
Running from C:\Software und Updates
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
GroupPolicyUsers\S-1-5-21-16454681-2363975253-3241007257-1002\User: Group Policy restriction detected <======= ATTENTION
GroupPolicyUsers\S-1-5-21-16454681-2363975253-3241007257-1000\User: Group Policy restriction detected <======= ATTENTION
*****************
C:\WINDOWS\system32\GroupPolicyUsers\S-1-5-21-16454681-2363975253-3241007257-1002\User => Moved successfully.
C:\WINDOWS\system32\GroupPolicyUsers\S-1-5-21-16454681-2363975253-3241007257-1000\User => Moved successfully.
The system needed a reboot.
==== End of Fixlog ====
Malwarebytes Anti-Malware
www.malwarebytes.org
Update, 10.05.2014 13:26:11, SYSTEM, USER-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 10.05.2014 13:26:25, SYSTEM, USER-PC, Manual, Malware Database, 2014.3.4.9, 2014.5.10.3,
(end)
AdwCleaner Logfile: Code:
# AdwCleaner v3.207 - Bericht erstellt am 10/05/2014 um 14:14:07
# Aktualisiert 05/05/2014 von Xplode
# Betriebssystem : Windows 8.1 Pro (64 bits)
# Benutzername :
# Gestartet von : C:\Software und Updates\adwcleaner_3.2.0.7.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\freezon\AppData\Local\Temp\FoxTab
Ordner Gelöscht : C:\Users\freezon\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\FoxTab
Ordner Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\toolbar@ask.com
Ordner Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\mail@shopping-preise.de
Datei Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
Datei Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\searchplugins\11-suche.xml
Datei Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\searchplugins\Askcom.xml
Datei Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\searchplugins\BabylonMngr.xml
Datei Gelöscht : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\OCS
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Mozilla Firefox v29.0 (de)
[ Datei : C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\prefs.js ]
Zeile gelöscht : user_pref("avg.install.userHPSettings", "hxxp://search.babylon.com/?affID=110191&tt=3612_1&babsrc=HP_ss&mntrId=28f5bd6f000000000000002682a33a0a");
Zeile gelöscht : user_pref("avg.install.userSPSettings", "Search the web (Babylon)");
Zeile gelöscht : user_pref("browser.babylon.HPOnNewTab", "search.babylon.com");
Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://search.babylon.com/?affID=110191&tt=3612_1&babsrc=NT_ss&mntrId=28f5bd6f000000000000002682a33a0a");
Zeile gelöscht : user_pref("browser.search.order.1", "Search the web (Babylon)");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.admin", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.appId", "{BDB69379-802F-4eaf-B541-F8DE92DD98DB}");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.babExt", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.babTrack", "affID=110191&tt=3612_1");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.babext", "babExt");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.babtrack", "babTrack");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.bbDpng", "12");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.bbdpng", 7);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.cntry", "DE");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.dfltLng", "en");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.dfltlng", "en");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.dfltsrch", "false");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.envrmnt", "production");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.excTlbr", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.firstrun", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.hdrMd5", "C04CD57800B35C8CB0A284BBB969572B");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.hmpg", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.hrdid", "28f5bd6f000000000000002682a33a0a");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.id", "28f5bd6f000000000000002682a33a0a");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.instlDay", "15588");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.instlday", "15588");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.instlref", "sst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.isdcmntcmplt", "false");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.keywordurl", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.lastVrsnTs", "1.6.9.1219:50:49");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.lastdp", 11);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.mntrvrsn", "1.3.1");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.newTab", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar.newtab", "false");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.newtaburl", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.pnu_base", "{\"newVrsn\":\"41\",\"lastVrsn\":\"41\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"true\",\"msgTs\":0}");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prdct", "BabylonToolbar");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtnrId", "babylon");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.prtnrid", "babylon");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.savedVrsnTs", "1");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.sg", "azb");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.smplGrp", "azb");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.smplgrp", "azb");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.srcext", "ss");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.srch", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.srchprvdr", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.tlbrSrchUrl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=28f5bd6f000000000000002682a33a0a&q=");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.tlbrid", "base");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.tlbrsrchurl", "hxxp://search.babylon.com/?babsrc=TB_def&mntrId=28f5bd6f000000000000002682a33a0a&q=");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.vrsn", "1.6.9.12");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.vrsnTs", "1.6.9.1219:50:49");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.vrsni", "1.6.9.12");
Zeile gelöscht : user_pref("extensions.BabylonToolbar.vrsnts", "1.6.9.1219:50:49");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.babExt", "");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.babTrack", "affID=110191&tt=3612_1");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.hardId", "7a23f120000000000000002682a33a0a");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.id", "7a23f120000000000000002682a33a0a");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.instlDay", "15472");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTab", false);
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.newTabUrl", "hxxp://search.babylon.com/?affID=111304&tt=100512_3_&babsrc=NT_ss&mntrId=7a23f120000000000000002682a33a0a");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.6.9.1219:50:49");
Zeile gelöscht : user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
Zeile gelöscht : user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\");
Zeile gelöscht : user_pref("extensions.asktb.cbid", "JM");
Zeile gelöscht : user_pref("extensions.asktb.config-updated", true);
Zeile gelöscht : user_pref("extensions.asktb.crumb", "2011.06.28+14.39.51-toolbar008iad-DE-SGFsbGUsR2VybWFueQ%3D%3D");
Zeile gelöscht : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&o={o}&l={l}&gct=bar");
Zeile gelöscht : user_pref("extensions.asktb.dtid", "YYYYYYYYDE");
Zeile gelöscht : user_pref("extensions.asktb.fresh-install", false);
Zeile gelöscht : user_pref("extensions.asktb.guid", "c88b45f2-aa6a-4af3-8830-1992a48f0d5d");
Zeile gelöscht : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com\", \"www.facebook.com\", \"www.playsushi.com\", \"WWW.google.com\", \"hxxps://websearch.ask.com\", [...]
Zeile gelöscht : user_pref("extensions.asktb.if", "first");
Zeile gelöscht : user_pref("extensions.asktb.l", "dis");
Zeile gelöscht : user_pref("extensions.asktb.last-config-req", "1309506503646");
Zeile gelöscht : user_pref("extensions.asktb.locale", "de_DE");
Zeile gelöscht : user_pref("extensions.asktb.location", "Halle,Germany");
Zeile gelöscht : user_pref("extensions.asktb.notification-shown", true);
Zeile gelöscht : user_pref("extensions.asktb.o", "100000080");
Zeile gelöscht : user_pref("extensions.asktb.overlay-reloaded-using-restart", true);
Zeile gelöscht : user_pref("extensions.asktb.qsrc", "2871");
Zeile gelöscht : user_pref("extensions.asktb.r", "3");
Zeile gelöscht : user_pref("extensions.asktb.sa", "NO");
Zeile gelöscht : user_pref("extensions.asktb.search-suggestions-enabled", true);
Zeile gelöscht : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false);
Zeile gelöscht : user_pref("extensions.asktb.themeid", "");
Zeile gelöscht : user_pref("extensions.asktb.to", "");
Zeile gelöscht : user_pref("extensions.asktb.version", "5.12.2.17367");
Zeile gelöscht : user_pref("extensions.foxlingo.addit.defaultAddons", "{ \"software\": {\"7\": {\"id\": \"7\",\"title\": \"Billeo\",\"type\": \"XPI\",\"url\": \"hxxps://addons.mozilla.org/firefox/downloads/file/103313[...]
Zeile gelöscht : user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir)/.*|hxxp://.*depositfiles.com/(([a-z]{2})/files/|auth-).*|hxxp://(www.)*digg.com/(.{5}|.{6})$|hxxp:[...]
Zeile gelöscht : user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
Zeile gelöscht : user_pref("sweetim.toolbar.previous.browser.search.defaultenginename", "Search the web (Babylon)");
Zeile gelöscht : user_pref("sweetim.toolbar.urls.homepage", "hxxp://search.babylon.com/?affID=110191&tt=3612_1&babsrc=HP_ss&mntrId=28f5bd6f000000000000002682a33a0a");
*************************
AdwCleaner[R0].txt - [11350 octets] - [10/05/2014 13:52:03]
AdwCleaner[S0].txt - [11224 octets] - [10/05/2014 14:14:07]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [11285 octets] ########## --- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 Pro x64
Ran by on 10.05.2014 at 14:22:29,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted the following from C:\Users\AppData\Roaming\mozilla\firefox\profiles\2w8vpm12.default\prefs.js
user_pref("extensions.AVIRA-V7.com.avira.dnt.rules", "\"{\\\"Version\\\":38,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Anal
user_pref("extensions.AVIRA-V7.domain", "\"avira.search.ask.com\"");
user_pref("extensions.linkextend.defaultsearchengine", "ixquick");
user_pref("extensions.skipscreen.hostMatchStr", "hxxp://www.4shared.com/(get|audio|file|document|dir)/.*|hxxp://.*depositfiles.com/(([a-z]{2})/files/|auth-).*|hxxp://(www.)*di
user_pref("google.toolbar.button_option.cached.gtbSearchBlogs", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchBlogs\" t
user_pref("google.toolbar.button_option.cached.gtbSearchPhotos", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchPhotos\"
user_pref("google.toolbar.button_option.cached.gtbSearchScholar", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.only.xul\" id=\"gtbSearchScholar
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_CTK0Y7F4MTG6NKYH03WT-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.button_option.cached.gtbstoolbar-google-com_J66T77NJDBMW4FEUU7FA-xml", "<toolbarbutton xmlns=\"hxxp://www.mozilla.org/keymaster/gatekeeper/there.is.o
user_pref("google.toolbar.search-icon", "data:image/x-icon;base64,AAABAAEAEBAAAAEAIABoBAAAFgAAACgAAAAQAAAAIAAAAAEAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA7PT7/3zF6/9Ptu//RbHx/
user_pref("tweaktube.pref.cacheInfo", "({'hxxp://wedata.net/databases/AutoPagerize/items.json':{url:\"hxxp://wedata.net/databases/AutoPagerize/items.json\", expire:(new Date(1
Emptied folder: C:\Users\freezon\AppData\Roaming\mozilla\firefox\profiles\2w8vpm12.default\minidumps [25 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 10.05.2014 at 14:25:56,32
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-05-2014
Platform: Windows 8.1 Pro (Update 1) (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(Cybits AG) C:\Program Files\SURF-SITTER PC\cy-Service_2.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Cybits AG) C:\Program Files\SURF-SITTER PC\cy-Service.exe
(Cybits AG) C:\Program Files\SURF-SITTER PC\AutoUpdaterService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Dropbox, Inc.) C:\Users\freezon\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_206.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6334096 2012-10-17] (Realtek semiconductor)
HKLM\...\Run: [SynLenovoGestureMgr] => C:\Program Files\Synaptics\SynTP\SynLenovoGestureMgr.exe [665400 2012-08-27] (Synaptics)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-27] (Synaptics Incorporated)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1225920 2014-04-30] (NVIDIA Corporation)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2199840 2014-04-30] (NVIDIA Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13647576 2013-08-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\...\Run: [BTMTrayAgent] => C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll [7830328 2013-05-21] (Motorola Solutions, Inc.)
HKLM\...\Run: [SURF-SITTER PC] => C:\Program Files\SURF-SITTER PC\cy-Software.exe [1403904 2013-11-27] ()
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3933496 2012-09-20] (Logitech, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17111056 2014-05-05] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2014-05-05] (Lenovo(beijing) Limited)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [174296 2014-03-04] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [148016 2014-03-04] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CineForm Status.lnk
ShortcutTarget: CineForm Status.lnk -> C:\Program Files (x86)\CineForm\Tools\GoProCineFormStatusViewer.exe (GoPro)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WISO Mein Steuer-Sparbuch heute.lnk
ShortcutTarget: WISO Mein Steuer-Sparbuch heute.lnk -> C:\Program Files (x86)\WISO\Steuersoftware 2014\mshaktuell.exe ()
Startup: C:\Users\freezon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\freezon\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE8256536D551CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE,de;q=0.8,en-US;q=0.5,en;q=0.3
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll (IvoSoft)
BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll (IvoSoft)
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default
FF Homepage: hxxp://spiegelonline.de/
FF NetworkProxy: "http", "www-proxy.t-online.de"
FF NetworkProxy: "http_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_13_0_0_206.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.4 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF SearchPlugin: C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: German Dictionary - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2013-08-05]
FF Extension: ProxTube - Unblock YouTube - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\ich@maltegoetz.de [2013-12-11]
FF Extension: Leopard Mail-Default-Graphite - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\LeopardMailDefaultGraphite@reo-2007 [2013-08-05]
FF Extension: Google Toolbar for Firefox - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2013-08-05]
FF Extension: WOT - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-11-26]
FF Extension: DownloadHelper - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-25]
FF Extension: Block site - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc} [2013-11-11]
FF Extension: Personas Plus - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\personas@christopher.beard.xpi [2013-08-05]
FF Extension: SkipScreen - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\SkipScreen@SkipScreen.xpi [2013-08-05]
FF Extension: WEB.DE MailCheck - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\toolbar@web.de.xpi [2013-08-05]
FF Extension: YouTube to MP3 - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\youtube2mp3@mondayx.de.xpi [2013-08-05]
FF Extension: All-in-One Sidebar - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2013-08-05]
FF Extension: Webutation - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{15fe27f3-e5ab-2d59-4c5c-dadc7945bdbd}.xpi [2013-08-05]
FF Extension: Image Zoom - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013-08-05]
FF Extension: NoScript - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-08-05]
FF Extension: Googlebar Lite - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{79c50f9a-2ffe-4ee0-8a37-fae4f5dacd4f}.xpi [2013-08-05]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2013-08-05]
FF Extension: Adblock Plus - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-08-05]
FF Extension: BetterPrivacy - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-08-05]
FF Extension: FoxTab - C:\Users\freezon\AppData\Roaming\Mozilla\Firefox\Profiles\2w8vpm12.default\Extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi [2013-08-05]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1017424 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.)
R2 C88EDF03-FB60-44F4-AC70-FFF129414098; C:\Program Files\SURF-SITTER PC\cy-Service_2.exe [79872 2013-11-27] (Cybits AG)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-08-02] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1618888 2014-04-30] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21009352 2014-04-30] (NVIDIA Corporation)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
R2 surf-sitter; C:\Program Files\SURF-SITTER PC\cy-Service.exe [369664 2013-11-27] (Cybits AG)
R2 surf-sitter-Updater; C:\Program Files\SURF-SITTER PC\AutoUpdaterService.exe [320512 2013-11-27] (Cybits AG)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
S0 ADP80XX; C:\Windows\System32\drivers\ADP80XX.SYS [782176 2013-08-22] (PMC-Sierra)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [84720 2013-12-17] (Avira Operations GmbH & Co. KG)
S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Windows (R) Win 7 DDK provider)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-08-12] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [132920 2013-04-23] (Motorola Solutions, Inc.)
R3 cy_System; C:\Windows\System32\drivers\cy-wdriver.sys [37648 2013-11-27] (Cybits AG)
S3 iaLPSSi_GPIO; C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [24568 2013-07-30] (Intel Corporation)
S3 iaLPSSi_I2C; C:\Windows\System32\drivers\iaLPSSi_I2C.sys [99320 2013-07-25] (Intel Corporation)
S0 iaStorAV; C:\Windows\System32\drivers\iaStorAV.sys [651248 2013-08-10] (Intel Corporation)
R0 intelpep; C:\Windows\System32\drivers\intelpep.sys [39768 2013-11-11] (Microsoft Corporation)
S3 kbldfltr; C:\Windows\System32\drivers\kbldfltr.sys [22272 2013-09-30] (Microsoft Corporation)
S0 LSI_SAS3; C:\Windows\System32\drivers\lsi_sas3.sys [81760 2013-08-22] (LSI Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
R3 NdisVirtualBus; C:\Windows\System32\drivers\NdisVirtualBus.sys [16384 2013-08-22] (Microsoft Corporation)
S3 netvsc; C:\Windows\system32\DRIVERS\netvsc63.sys [87040 2013-08-22] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19744 2014-04-30] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
S3 ReFS; C:\Windows\System32\Drivers\ReFS.sys [924504 2014-02-22] (Microsoft Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8230160 2012-10-17] (Realtek Semiconductor Corp.)
S3 SerCx2; C:\Windows\System32\drivers\SerCx2.sys [146776 2013-10-26] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [43832 2012-08-27] (Synaptics Incorporated)
S0 stornvme; C:\Windows\System32\drivers\stornvme.sys [57176 2013-10-05] (Microsoft Corporation)
S3 UEFI; C:\Windows\System32\drivers\UEFI.sys [26976 2013-08-22] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation)
R0 Wof; C:\Windows\System32\Drivers\Wof.sys [157016 2014-03-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-10 14:25 - 2014-05-10 14:25 - 00002887 _____ () C:\Users\freezon\Desktop\JRT.txt
2014-05-10 14:22 - 2014-05-10 14:22 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-10 13:52 - 2014-05-10 14:14 - 00000000 ____D () C:\AdwCleaner
2014-05-10 13:26 - 2014-05-10 13:48 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-10 13:26 - 2014-05-10 13:26 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-10 13:25 - 2014-05-10 13:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-10 13:25 - 2014-05-10 13:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-10 13:25 - 2014-05-10 13:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-10 13:25 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-05-10 13:25 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-05-10 13:25 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-05-10 11:31 - 2014-05-10 11:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-05-09 19:52 - 2014-05-09 19:52 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp
2014-05-09 19:52 - 2014-03-31 18:42 - 00040392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2014-05-09 19:52 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2014-05-08 17:44 - 2014-05-08 17:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-08 17:44 - 2014-05-08 17:44 - 00000000 ____D () C:\Program Files\7-Zip
2014-05-08 17:34 - 2014-05-10 14:29 - 00000000 ____D () C:\FRST
2014-05-07 13:39 - 2014-05-07 13:39 - 00001219 _____ () C:\Users\freezon\Desktop\Any Video Converter.lnk
2014-05-07 13:39 - 2014-05-07 13:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft
2014-05-07 13:39 - 2014-05-07 13:39 - 00000000 ____D () C:\Program Files (x86)\AnvSoft
2014-05-05 22:51 - 2014-05-05 22:51 - 00006916 _____ () C:\WINDOWS\DPINST.LOG
2014-05-05 22:51 - 2014-05-05 22:51 - 00000000 ____D () C:\ProgramData\Energy Management
2014-05-05 22:51 - 2014-05-05 22:51 - 00000000 ____D () C:\Program Files\Lenovo
2014-05-05 22:51 - 2014-05-05 22:51 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2014-05-05 22:51 - 2014-05-05 22:50 - 00039008 _____ (Lenovo.) C:\WINDOWS\system32\Drivers\LhdX64.sys
2014-05-05 22:51 - 2014-05-05 22:50 - 00019872 _____ (Lenovo (Beijing) Limited) C:\WINDOWS\system32\LenovoSDKEmSubSystem.dll
2014-05-05 22:42 - 2014-05-10 14:16 - 00001736 _____ () C:\WINDOWS\PFRO.log
2014-05-05 22:42 - 2014-05-05 22:42 - 00636864 _____ () C:\WINDOWS\Minidump\050514-48375-01.dmp
2014-05-05 22:06 - 2014-05-10 10:40 - 00002424 _____ () C:\WINDOWS\setupact.log
2014-05-05 22:06 - 2014-05-05 22:06 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-05-05 21:55 - 2014-05-05 22:03 - 00036866 _____ () C:\WINDOWS\system32\energy-report.html
2014-05-04 18:34 - 2014-05-04 18:34 - 00004253 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-04 18:34 - 2014-05-04 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-04 18:34 - 2014-04-14 20:13 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-05-04 18:34 - 2014-04-14 20:05 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-05-04 18:34 - 2014-04-14 20:05 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-05-04 18:34 - 2014-04-14 20:04 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-05-02 20:02 - 2014-04-29 16:01 - 23547904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-05-02 20:02 - 2014-04-29 14:48 - 17384448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-05-02 19:29 - 2014-05-02 19:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-05-02 19:29 - 2014-05-02 19:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-05-01 11:25 - 2014-05-01 11:25 - 00012154 _____ () C:\Users\freezon\AppData\Local\recently-used.xbel
2014-04-30 08:55 - 2014-04-30 08:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-26 20:00 - 2014-04-26 20:00 - 00000000 ____D () C:\Users\freezon\Documents\Any Video Converter
2014-04-26 20:00 - 2014-04-26 20:00 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\AnvSoft
2014-04-25 19:18 - 2014-05-05 21:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPEG4E
2014-04-25 19:18 - 2014-04-25 19:23 - 00000000 ____D () C:\Users\freezon\AppData\Local\Video Converter
2014-04-25 19:18 - 2014-04-25 19:18 - 00000000 ____D () C:\Users\freezon\Documents\Video Converter
2014-04-25 19:17 - 2014-04-25 19:17 - 00000000 ____D () C:\ProgramData\VideoConverter
2014-04-25 13:19 - 2014-04-25 13:19 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\DropboxMaster
2014-04-24 11:59 - 2014-05-10 14:20 - 01259885 _____ () C:\WINDOWS\WindowsUpdate.log
2014-04-24 11:50 - 2014-04-24 11:50 - 00000000 ____D () C:\Users\freezon\Documents\ProcAlyzer Dumps
2014-04-24 11:02 - 2014-03-06 11:07 - 00450709 _____ () C:\WINDOWS\system32\Drivers\etc\hosts.20140424-110243.backup
2014-04-23 13:52 - 2014-04-23 13:52 - 00000000 ____D () C:\ProgramData\WatchMyCam
2014-04-20 21:48 - 2014-04-20 22:28 - 00000000 ____D () C:\Users\freezon\Desktop\Haus
2014-04-20 10:17 - 2014-04-20 10:17 - 00284864 _____ (IvoSoft) C:\WINDOWS\system32\StartMenuHelper64.dll
2014-04-20 10:17 - 2014-04-20 10:17 - 00244928 _____ (IvoSoft) C:\WINDOWS\SysWOW64\StartMenuHelper32.dll
2014-04-18 15:11 - 2014-04-09 14:00 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-04-18 15:11 - 2014-04-09 05:32 - 00190976 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2014-04-18 15:11 - 2014-04-09 05:31 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2014-04-18 15:11 - 2014-04-09 05:23 - 01705984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2014-04-18 15:11 - 2014-04-09 05:21 - 03408896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
==================== One Month Modified Files and Folders =======
2014-05-10 14:29 - 2014-05-08 17:34 - 00000000 ____D () C:\FRST
2014-05-10 14:29 - 2013-07-05 13:46 - 00000000 ____D () C:\Software und Updates
2014-05-10 14:25 - 2014-05-10 14:25 - 00002887 _____ () C:\Users\freezon\Desktop\JRT.txt
2014-05-10 14:24 - 2013-09-30 06:14 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-05-10 14:24 - 2013-09-30 05:56 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2014-05-10 14:24 - 2013-09-30 05:56 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2014-05-10 14:22 - 2014-05-10 14:22 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-05-10 14:20 - 2014-04-24 11:59 - 01259885 _____ () C:\WINDOWS\WindowsUpdate.log
2014-05-10 14:18 - 2013-08-21 10:05 - 00000000 ___RD () C:\Users\freezon\Dropbox
2014-05-10 14:18 - 2013-08-21 10:03 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\Dropbox
2014-05-10 14:17 - 2013-10-19 15:50 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-05-10 14:17 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-05-10 14:16 - 2014-05-05 22:42 - 00001736 _____ () C:\WINDOWS\PFRO.log
2014-05-10 14:14 - 2014-05-10 13:52 - 00000000 ____D () C:\AdwCleaner
2014-05-10 14:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-05-10 13:56 - 2013-08-03 16:17 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-16454681-2363975253-3241007257-1000
2014-05-10 13:48 - 2014-05-10 13:26 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-05-10 13:43 - 2013-10-25 07:53 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\ClassicShell
2014-05-10 13:43 - 2013-08-24 20:40 - 00000000 ____D () C:\Users\freezon\AppData\Local\CrashDumps
2014-05-10 13:26 - 2014-05-10 13:26 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-10 13:26 - 2014-05-10 13:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-10 13:25 - 2014-05-10 13:25 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-10 13:25 - 2014-05-10 13:25 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-10 13:19 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-05-10 12:27 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-05-10 11:31 - 2014-05-10 11:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2014-05-10 11:31 - 2013-10-25 07:54 - 00000000 ____D () C:\ProgramData\ClassicShell
2014-05-10 11:31 - 2013-08-03 16:34 - 00000000 ____D () C:\Program Files\Classic Shell
2014-05-10 10:43 - 2013-08-05 20:37 - 00001454 _____ () C:\Users\Public\Desktop\Free Audio Converter.lnk
2014-05-10 10:43 - 2013-08-05 20:35 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\DVDVideoSoft
2014-05-10 10:43 - 2013-08-05 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-05-10 10:43 - 2013-08-05 20:35 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2014-05-10 10:40 - 2014-05-05 22:06 - 00002424 _____ () C:\WINDOWS\setupact.log
2014-05-09 19:52 - 2014-05-09 19:52 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp
2014-05-08 17:44 - 2014-05-08 17:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-05-08 17:44 - 2014-05-08 17:44 - 00000000 ____D () C:\Program Files\7-Zip
2014-05-07 13:46 - 2013-09-26 22:26 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\MyPhoneExplorer
2014-05-07 13:39 - 2014-05-07 13:39 - 00001219 _____ () C:\Users\freezon\Desktop\Any Video Converter.lnk
2014-05-07 13:39 - 2014-05-07 13:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnvSoft
2014-05-07 13:39 - 2014-05-07 13:39 - 00000000 ____D () C:\Program Files (x86)\AnvSoft
2014-05-06 21:26 - 2013-08-24 14:19 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\vlc
2014-05-05 22:51 - 2014-05-05 22:51 - 00006916 _____ () C:\WINDOWS\DPINST.LOG
2014-05-05 22:51 - 2014-05-05 22:51 - 00000000 ____D () C:\ProgramData\Energy Management
2014-05-05 22:51 - 2014-05-05 22:51 - 00000000 ____D () C:\Program Files\Lenovo
2014-05-05 22:51 - 2014-05-05 22:51 - 00000000 ____D () C:\Program Files (x86)\Lenovo
2014-05-05 22:51 - 2013-12-03 22:41 - 00000000 ____D () C:\Program Files\DIFX
2014-05-05 22:51 - 2013-08-03 16:43 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-05-05 22:50 - 2014-05-05 22:51 - 00039008 _____ (Lenovo.) C:\WINDOWS\system32\Drivers\LhdX64.sys
2014-05-05 22:50 - 2014-05-05 22:51 - 00019872 _____ (Lenovo (Beijing) Limited) C:\WINDOWS\system32\LenovoSDKEmSubSystem.dll
2014-05-05 22:50 - 2012-07-08 20:22 - 00035600 _____ (Lenovo Corporation) C:\WINDOWS\system32\Drivers\AcpiVpc.sys
2014-05-05 22:50 - 2012-02-21 05:48 - 02356592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WudfUpdate_01011.dll
2014-05-05 22:42 - 2014-05-05 22:42 - 00636864 _____ () C:\WINDOWS\Minidump\050514-48375-01.dmp
2014-05-05 22:42 - 2014-03-10 14:19 - 00000000 ____D () C:\WINDOWS\Minidump
2014-05-05 22:36 - 2014-02-14 09:17 - 00000000 ____D () C:\Program Files (x86)\Bluetooth Suite
2014-05-05 22:36 - 2013-10-19 15:55 - 00000000 ____D () C:\Users\freezon
2014-05-05 22:23 - 2013-08-03 16:59 - 00000000 ____D () C:\ProgramData\Downloaded Installations
2014-05-05 22:06 - 2014-05-05 22:06 - 00000000 _____ () C:\WINDOWS\setuperr.log
2014-05-05 22:03 - 2014-05-05 21:55 - 00036866 _____ () C:\WINDOWS\system32\energy-report.html
2014-05-05 21:44 - 2013-08-05 20:34 - 00000838 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-05-05 21:44 - 2013-08-05 20:34 - 00000000 ____D () C:\Program Files\CCleaner
2014-05-05 21:42 - 2014-04-09 21:58 - 00000000 ____D () C:\Users\freezon\AppData\Local\Deployment
2014-05-05 21:41 - 2014-04-25 19:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MPEG4E
2014-05-05 00:18 - 2013-08-05 20:53 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\Audacity
2014-05-04 18:34 - 2014-05-04 18:34 - 00004253 _____ () C:\WINDOWS\SysWOW64\jupdate-1.7.0_55-b14.log
2014-05-04 18:34 - 2014-05-04 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-05-04 18:34 - 2013-12-13 11:44 - 00000000 ____D () C:\ProgramData\Oracle
2014-05-04 18:34 - 2013-12-13 11:44 - 00000000 ____D () C:\Program Files (x86)\Java
2014-05-03 21:53 - 2013-08-07 07:48 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-02 19:29 - 2014-05-02 19:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-05-02 19:29 - 2014-05-02 19:29 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-05-02 14:37 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2014-05-02 10:27 - 2013-08-03 17:08 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-01 19:28 - 2013-08-24 20:40 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\dvdcss
2014-05-01 11:32 - 2013-09-20 17:02 - 00000000 ____D () C:\Users\freezon\.gimp-2.8
2014-05-01 11:25 - 2014-05-01 11:25 - 00012154 _____ () C:\Users\freezon\AppData\Local\recently-used.xbel
2014-05-01 11:13 - 2013-09-20 17:11 - 00000000 ____D () C:\Users\freezon\AppData\Local\gtk-2.0
2014-04-30 20:29 - 2013-10-28 16:06 - 01225920 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2014-04-30 20:29 - 2013-10-28 16:06 - 01081112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2014-04-30 08:58 - 2014-04-30 08:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-04-29 16:01 - 2014-05-02 20:02 - 23547904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-04-29 14:48 - 2014-05-02 20:02 - 17384448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-04-29 08:31 - 2013-11-26 15:41 - 00008356 _____ () C:\Users\freezon\Documents\capella.log
2014-04-28 17:03 - 2013-08-07 09:52 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-27 09:01 - 2013-08-05 17:18 - 00000000 ____D () C:\Users\freezon\AppData\Local\Adobe
2014-04-26 20:00 - 2014-04-26 20:00 - 00000000 ____D () C:\Users\freezon\Documents\Any Video Converter
2014-04-26 20:00 - 2014-04-26 20:00 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\AnvSoft
2014-04-25 19:23 - 2014-04-25 19:18 - 00000000 ____D () C:\Users\freezon\AppData\Local\Video Converter
2014-04-25 19:19 - 2014-02-20 13:18 - 00005120 _____ () C:\Users\freezon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-04-25 19:18 - 2014-04-25 19:18 - 00000000 ____D () C:\Users\freezon\Documents\Video Converter
2014-04-25 19:17 - 2014-04-25 19:17 - 00000000 ____D () C:\ProgramData\VideoConverter
2014-04-25 13:19 - 2014-04-25 13:19 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\DropboxMaster
2014-04-25 13:19 - 2013-08-21 10:05 - 00001039 _____ () C:\Users\freezon\Desktop\Dropbox.lnk
2014-04-25 13:19 - 2013-08-21 10:04 - 00000000 ____D () C:\Users\freezon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-04-25 13:19 - 2013-08-03 16:12 - 00000000 ___RD () C:\Users\freezon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-24 13:28 - 2013-07-06 11:18 - 00000000 ____D () C:\Users\freezon\Documents\Bluetooth Folder
2014-04-24 11:50 - 2014-04-24 11:50 - 00000000 ____D () C:\Users\freezon\Documents\ProcAlyzer Dumps
2014-04-24 11:50 - 2013-08-05 20:38 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2014-04-24 07:30 - 2014-04-08 07:46 - 00000000 ____D () C:\Users\Public\Documents\surf-sitter
2014-04-23 13:52 - 2014-04-23 13:52 - 00000000 ____D () C:\ProgramData\WatchMyCam
2014-04-23 02:24 - 2013-11-14 21:27 - 00693240 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-04-23 02:24 - 2013-11-14 21:27 - 00105464 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-22 17:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-04-20 22:28 - 2014-04-20 21:48 - 00000000 ____D () C:\Users\freezon\Desktop\Haus
2014-04-20 10:17 - 2014-04-20 10:17 - 00284864 _____ (IvoSoft) C:\WINDOWS\system32\StartMenuHelper64.dll
2014-04-20 10:17 - 2014-04-20 10:17 - 00244928 _____ (IvoSoft) C:\WINDOWS\SysWOW64\StartMenuHelper32.dll
2014-04-19 11:38 - 2013-11-14 20:40 - 00000000 ____D () C:\Users\freezon\AppData\Local\NVIDIA Corporation
2014-04-19 11:38 - 2013-10-19 15:49 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-04-19 11:38 - 2013-10-19 15:49 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-04-19 11:32 - 2013-08-22 15:25 - 00008192 ___SH () C:\WINDOWS\system32\config\ELAM
2014-04-14 20:13 - 2014-05-04 18:34 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-04-14 20:05 - 2014-05-04 18:34 - 00264616 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-04-14 20:05 - 2014-05-04 18:34 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-04-14 20:04 - 2014-05-04 18:34 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-04-13 13:18 - 2014-04-05 16:05 - 00000000 ____D () C:\ProgramData\Gallery
Some content of TEMP:
====================
C:\Users\freezon\AppData\Local\Temp\avgnt.exe
C:\Users\freezon\AppData\Local\Temp\Checkupdate.exe
C:\Users\freezon\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpd3yhzp.dll
C:\Users\freezon\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\freezon\AppData\Local\Temp\gcapi_dll.dll
C:\Users\freezon\AppData\Local\Temp\gtapi_signed.dll
C:\Users\freezon\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-10 13:56
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Vielen Dank für die Hilfestellung !! |