mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 28.06.2014
Suchlauf-Zeit: 21:39:43
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.28.04
Rootkit Datenbank: v2014.06.23.02
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: sebastian
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 334712
Verstrichene Zeit: 11 Min, 21 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe, 2392, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 33
PUP.Optional.SearchProtect.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [e9eb5a23a3d8f442d4c23e53798859a7],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{21EAF666-26B3-4a3c-ABD0-CA2F5A326744}, In Quarantäne, [fcd84934b2c90f27790a420b5fa39e62],
PUP.Optional.VBates, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{21EAF666-26B3-4A3C-ABD0-CA2F5A326744}, In Quarantäne, [fcd84934b2c90f27790a420b5fa39e62],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [34a06617186367cf0fa13512aa589868],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{708D0DD7-FBC0-4437-B525-C098F450A62C}, In Quarantäne, [e3f181fca3d8d95d3b73341319e9619f],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr, In Quarantäne, [4f85f08de893b1856b441d668082ef11],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchHlpr.1, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchHlpr.1, In Quarantäne, [ddf70a73e09bbf7700af8bf860a221df],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd, In Quarantäne, [399b3746cdaefe38f9b7394aaf5353ad],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\buenosearch.buenosearchdskBnd.1, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\buenosearch.buenosearchdskBnd.1, In Quarantäne, [e8ecbcc1334815214e625d26f60c20e0],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\V-bates, In Quarantäne, [be163e3f156655e14bb3d0025ca6df21],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\esrv.buenosearchESrvc, In Quarantäne, [2fa5097492e9d66009803a93da28a759],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\CLASSES\esrv.buenosearchESrvc.1, In Quarantäne, [9e366f0eb5c6a88e3a4f0dc0ec16b050],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\buenosearch LTD, In Quarantäne, [3d97463791ea68ce1a6ca726be446b95],
PUP.Optional.HQVid.A, HKLM\SOFTWARE\WOW6432NODE\HQVid8.1b, In Quarantäne, [8252a8d5b6c50d292d2cc6f738ca3dc3],
PUP.Optional.MediaPlayerplus.A, HKLM\SOFTWARE\WOW6432NODE\MediaPlayerplus, In Quarantäne, [a23258254c2f8fa720c4f3d04bb7659b],
PUP.Optional.MegaBrowse.A, HKLM\SOFTWARE\WOW6432NODE\Mega Browse, In Quarantäne, [f8dc5924106bca6c4d0bdfe944be0cf4],
PUP.Optional.VbatesHelper.A, HKLM\SOFTWARE\WOW6432NODE\V-bates, In Quarantäne, [4a8ad9a49edd8aac0fefb22037cb1de3],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.buenosearchESrvc, In Quarantäne, [05cff38abebd7eb8dfaa903d0200a55b],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.buenosearchESrvc.1, In Quarantäne, [def63a436219eb4b6a1f27a66c9615eb],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\acfoobbgoakpihljnfedbcfaipcdlfhk, In Quarantäne, [8252a7d6235850e6ad215e92c53e25db],
PUP.Optional.Linkury.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{BC0BF363-63AB-4FF7-8EF1-AE0D7F711B24}, In Quarantäne, [12c20a73f388a78f21a23e7926dcd62a],
PUP.Optional.VbatesHelper.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\V-bates Updater, In Quarantäne, [567eaad32a515dd9ac4fb71b05fddc24],
PUP.Optional.Feven.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\Freeven Pro 1.3, In Quarantäne, [e1f3700d5c1f84b24550a110ab57738d],
PUP.Optional.HQVid.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQVid8.1b, In Quarantäne, [5381c2bbd4a70f27c2958934b15114ec],
PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, In Quarantäne, [f1e308755e1d5dd95393982b44bef808],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\buenosearch LTD, In Quarantäne, [805499e45a21a195dcab1cb1bf439b65],
PUP.Optional.MegaBrowse.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Mega Browse, In Quarantäne, [fcd8cab3e39886b0fc5b18b03bc7f60a],
PUP.Optional.HQVid.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\HQVid8.1b, In Quarantäne, [a52fa4d9a1daec4a97c0ba031ee47d83],
PUP.Optional.MediaPlayerplus.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\MediaPlayerplus, In Quarantäne, [6c68afce7cff77bf5f87d0f3b9490df3],
Registrierungswerte: 1
PUP.Optional.QuickStart.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\EXTENDS|appid, quick_start@gmail.com, In Quarantäne, [5c783449dc9f92a46ac8cde2976b7e82]
Registrierungsdaten: 8
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[5480e39a1c5f1125d90aa5e5dc28c33d]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[ffd5324bde9d7db9ba99ee9cae56b54b]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS5PD3rJOgw1pGzhTiN_LeZ3h5uqN9RPSYE5jaU9HNvWzyB5Fd9mOdB-PM7Siu3UQ,,, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS5PD3rJOgw1pGzhTiN_LeZ3h5uqN9RPSYE5jaU9HNvWzyB5Fd9mOdB-PM7Siu3UQ,,),Ersetzt,[f8dc14692556e94d33217b0f73915fa1]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[00d4b1cc6516979f72e05238a55f9a66]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[775d2c510a71fc3a8cc9800ae81c8c74]
PUP.Optional.Snapdo, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[cd075825d4a70f2774e25139a85c629e]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPGr6JN_C9Okvk3V9BHMT-IkVs3eDgJlBATeRnAqXYyYJDXLfK6eZDr--M9JXGUna07URU8dr5QfLqLUHw7Vl-zOt8XOL-dVu3NLPkZRNfQM4bHbuz9Q3SolVUfSfsupZS1VhESFPTU8pzUbzGWkT_hy7GVFtFSxYfYsBbOgeIEKRN7m9FX2vT8StDKG5HdHg,,&q={searchTerms}),Ersetzt,[963ea1dc3a41c175f3fb4f31a262847c]
PUP.Optional.Trovi.A, HKU\S-1-5-21-398813873-3760832578-3833595727-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=, Gut: (www.google.com), Schlecht: (hxxp://www.trovi.com/?gd=&ctid=CT3318522&octid=EB_ORIGINAL_CTID&ISID=M57ED6353-45C1-4274-B850-1AAD6175C3FE&SearchSource=55&CUI=&UM=5&UP=SPD6CDF09F-C0F2-40FD-A6AA-49987178B7D0&SSPV=),Ersetzt,[f1e3d2ab9eddfb3b31f1c8b857ad8c74]
Ordner: 21
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk, In Quarantäne, [8c48d8a577049b9b6a9f910a26dc51af],
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54],
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54],
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54],
Adware.EoRezo, C:\Program Files (x86)\fst_de_47, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a],
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1],
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\components, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1],
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\content, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, In Quarantäne, [ab295429eb902511a350aefb778bda26],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [ab295429eb902511a350aefb778bda26],
PUP.Optional.CrossRider.A, C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd, In Quarantäne, [4f85add01a611c1a68920a9f6c966c94],
PUP.Optional.CrossRider.A, C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpieepnfhpcpkjklohnpmmmmdhcbmd\1.26.24_0, In Quarantäne, [4f85add01a611c1a68920a9f6c966c94],
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\update, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73],
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer, In Quarantäne, [15bf5b22621972c4af18bceece34ad53],
Dateien: 55
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe, Löschen bei Neustart, [e9eb5a23a3d8f442d4c23e53798859a7],
PUP.Optional.SuperCoolApps, C:\Users\sebastian\Downloads\AdobeFlashPlayer.exe, In Quarantäne, [07cd0f6ea4d752e4d58e73a1ae56c040],
PUP.Optional.DomalQ, C:\Users\sebastian\Downloads\Setup_V2.exe, In Quarantäne, [508483fa1764ea4c216aa29ba35d9e62],
PUP.Optional.ReMarkIt.A, C:\Windows\Tasks\Re-markit_wd.job, In Quarantäne, [34a065184d2e6cca5062467ff40efc04],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\158.crx, In Quarantäne, [3f9596e73744171fc56c2d6d43bf16ea],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\158.xpi, In Quarantäne, [3f9596e73744171fc56c2d6d43bf16ea],
PUP.Optional.ReMarkIt.A, C:\Program Files (x86)\Re-markit Corp\Re-markit_wd.exe, Löschen bei Neustart, [3f9596e73744171fc56c2d6d43bf16ea],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\124.json, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\MessageBox.xml, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\uninstallDlg2.xml, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bg.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bg1.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\bk_shadow.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\button.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\button1.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checkbox.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checkbox_select.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\checked.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\close.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\loading_bg.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\loading_light.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\min.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\scrollbar.bmp, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\Thumbs.db, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\unchecked.png, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code1.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code2.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code3.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code4.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code5.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\code6.jpg, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
PUP.Optional.WebsSearches.A, C:\Users\sebastian\AppData\Roaming\webssearches\images\code\Thumbs.db, In Quarantäne, [32a280fd4f2cb58107bcbbdf91713dc3],
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\upfst_de_47.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54],
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\user_profil.cyp, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54],
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10\cnf.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54],
Adware.EoRezo, C:\Users\sebastian\AppData\Local\fst_de_47\fst_de_47\1.10\eorezo.cyl, In Quarantäne, [9e36c2bb14674fe71d497d20649eac54],
Adware.EoRezo, C:\Program Files (x86)\fst_de_47\unins000.dat, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a],
Adware.EoRezo, C:\Program Files (x86)\fst_de_47\unins000.msg, In Quarantäne, [34a0cbb216656dc94821fba2689ab64a],
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\install.rdf, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1],
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF.xpt, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1],
PUP.Optional.SystemK.A, C:\Users\sebastian\AppData\Roaming\Settings Manager\systemk\content\overlay.xul, In Quarantäne, [53811d6033481b1bff3eb9f090721fe1],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [ab295429eb902511a350aefb778bda26],
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\1293297481.mxaddon, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef],
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\360-58360.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef],
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\58360.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef],
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\58360.xpi, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef],
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\59d0aba1-9438-4ba8-979a-e06b975a27f4.crx, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef],
PUP.Optional.HQVideo.A, C:\Program Files (x86)\HQ-V1.3\background.html, In Quarantäne, [be16b2cb4e2d37ffc03fc7e2738f11ef],
PUP.Optional.WPM.A, C:\ProgramData\WindowsProtectManger\log\wprotectmanager_2014-06-19[14-22-42-729].log, In Quarantäne, [2ba91865ee8da88e1783129843bf8d73],
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\1293297481.mxaddon, In Quarantäne, [15bf5b22621972c4af18bceece34ad53],
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\360-59599.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53],
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\59599.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53],
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\59599.xpi, In Quarantäne, [15bf5b22621972c4af18bceece34ad53],
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\background.html, In Quarantäne, [15bf5b22621972c4af18bceece34ad53],
PUP.Optional.VideoMediaPlayer.A, C:\Program Files (x86)\video MediaPlayer\d5da2132-5fc4-4df1-9e78-5533f7681ac1.crx, In Quarantäne, [15bf5b22621972c4af18bceece34ad53],
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner Code:
# AdwCleaner v3.213 - Bericht erstellt am 28/06/2014 um 22:01:11
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : sebastian - GHOTS
# Gestartet von : C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : vosr
Dienst Gelöscht : wStLibG64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\CCOupExettension
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\Settings Manager
Ordner Gelöscht : C:\Program Files (x86)\SupTab
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Freesofttoday
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\Genesis
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\PennyBee
Ordner Gelöscht : C:\Users\sebastian\AppData\Local\torch
Ordner Gelöscht : C:\Users\sebastian\AppData\LocalLow\DataMngr
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\AppCloudUpdater
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\AppSafe
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Settings Manager
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AppSafe
Ordner Gelöscht : C:\Users\sebastian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
Ordner Gelöscht : C:\Users\sebastian\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Chromatic Browser
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\torch
Datei Gelöscht : C:\Windows\System32\drivers\wStLibG64.sys
Datei Gelöscht : C:\Users\sebastian\daemonprocess.txt
Datei Gelöscht : C:\Users\sebastian\AppData\Local\AnyProtectScannerSetup.exe
Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.scan.quick.results
Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.scan.results
Datei Gelöscht : C:\Users\sebastian\AppData\Roaming\aps.uninstall.scan.results
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{c1f9049a-3290-4967-9a3d-448f242ce94c}]
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ActiverisAntiMalware_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MegaBrowse_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MegaBrowse_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateMegaBrowse_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateMegaBrowse_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilMegaBrowse_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\utilMegaBrowse_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{4CC15FBA-46A4-4CB5-BFAF-F2335365AE76}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5B6E533F-F78F-4525-B316-312BAF1295D1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{8322EB6E-B594-41F6-A30B-CF3F800E1874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{67FCE87F-F3EF-4A3C-87C2-8BD46E68807B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E6772887-C1E1-405E-94BB-D8760A1CF8DF}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0BDDE35F-64F7-49C3-99B2-404E899C49F7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{24236608-609C-42C5-B13C-A8A3EC921850}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{28B1A706-4B97-4EB1-8B32-125042685AD9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{33575A26-D9CF-40C6-8A3E-116F17201C7F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4BDFD19F-93D7-49CE-B554-5C215FDC0136}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7307CF0F-7173-4FBF-8649-B149916DD322}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{80A5E38C-5F6B-485F-BD97-0B5BE991FAD5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9544D727-A26F-4D57-AF38-4496088640EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{AC4C30BF-7D5F-4EAB-9C2A-454178F079AA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC6F9C26-93EA-4C6D-A4A7-C1FA333B4BBE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E975527B-ABE7-40B3-B5C1-385016913E3B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA4B5B1-6C76-4B20-BCDB-D41A93E79053}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\AppCloudUpdater
Schlüssel Gelöscht : HKCU\Software\AppSafe
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKLM\Software\AppSafe
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16921
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208\prefs.js ]
-\\ Google Chrome v
*************************
AdwCleaner[R1].txt - [8015 octets] - [28/06/2014 22:00:42]
AdwCleaner[S1].txt - [7673 octets] - [28/06/2014 22:01:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [7733 octets] ########## JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by sebastian on 28.06.2014 at 22:08:38,81
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 28.06.2014 at 22:14:26,82
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 28-06-2014 02
Ran by sebastian (administrator) on GHOTS on 28-06-2014 22:20:41
Running from C:\Users\sebastian\Pictures
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnSrv.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files\ASUS\P4G\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13263072 2012-12-12] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2013-04-26] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [168616 2013-12-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [141336 2013-12-10] (NVIDIA Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\sebastian\AppData\Roaming\Mozilla\Firefox\Profiles\vxl7d2rs.default-1403797085208
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3522.0110 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [{20d1f7b3-7721-4da0-b6f3-78bb4d7248f4}] - C:\Program Files (x86)\Browser Guard\browserguard.xpi
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR Extension: (CostMin) - C:\Users\sebastian\AppData\Local\Google\Chrome\User Data\Default\Extensions\dllhlfdnlcfcmfdgfpgffglpmifeaepi [2014-06-19]
==================== Services (Whitelisted) =================
R2 ASUS InstantOn; C:\Program Files\ASUS\P4G\InsOnSrv.exe [277120 2013-06-19] (ASUS)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
S2 0204171396638742mcinstcleanup; C:\Users\SEBAST~1\AppData\Local\Temp\020417~1.EXE -cleanup -nolog [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-26] (Microsoft Corporation)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [65784 2013-04-29] (ASUS Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-28] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\SEBAST~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
U0 msahci;
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:01 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-06-28 22:00 - 2014-06-28 22:01 - 00000000 ____D () C:\AdwCleaner
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:38 - 2014-06-28 22:06 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-28 21:37 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-28 21:37 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-28 21:37 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-28 21:36 - 2014-06-28 21:37 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:20 - 2014-06-27 17:28 - 00000000 ____D () C:\Qoobox
2014-06-27 17:20 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-27 17:20 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-27 17:20 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-27 17:20 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-27 17:19 - 2014-06-27 17:26 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 15:38 - 2014-06-28 22:20 - 00000000 ____D () C:\FRST
2014-06-26 13:48 - 2014-06-26 13:55 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:37 - 2014-06-26 13:39 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 12:54 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-26 12:54 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2014-06-26 12:54 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-26 12:54 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-26 12:54 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-26 12:54 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-26 12:54 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-26 12:54 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2014-06-26 12:52 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-26 12:52 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-06-26 12:52 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-06-26 12:52 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-06-26 12:52 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-26 12:52 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys
2014-06-26 12:52 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-06-26 12:52 - 2014-04-01 00:08 - 00387268 _____ () C:\Windows\system32\ApnDatabase.xml
2014-06-26 12:52 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wusa.exe
2014-06-26 12:52 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-06-26 12:52 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-26 12:52 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-20 18:08 - 2014-06-28 22:03 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:29 - 2014-06-26 13:39 - 00000000 ____D () C:\ProgramData\CDB
2014-06-19 14:21 - 2014-06-26 12:27 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
==================== One Month Modified Files and Folders =======
2014-06-28 22:20 - 2014-06-26 15:38 - 00000000 ____D () C:\FRST
2014-06-28 22:18 - 2014-06-28 22:18 - 02083328 _____ (Farbar) C:\Users\sebastian\Downloads\FRST64.exe
2014-06-28 22:14 - 2014-06-28 22:14 - 00000616 _____ () C:\Users\sebastian\Desktop\JRT.txt
2014-06-28 22:08 - 2014-06-28 22:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-28 22:07 - 2014-06-28 22:07 - 01016261 _____ (Thisisu) C:\Users\sebastian\Downloads\JRT.exe
2014-06-28 22:06 - 2014-06-28 21:38 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-28 22:05 - 2014-06-28 22:05 - 00007869 _____ () C:\Users\sebastian\Desktop\AdwCleaner[S1].txt
2014-06-28 22:04 - 2014-04-06 16:22 - 01414287 _____ () C:\Windows\WindowsUpdate.log
2014-06-28 22:03 - 2014-06-20 18:08 - 00035110 _____ () C:\Windows\PFRO.log
2014-06-28 22:03 - 2014-04-03 18:49 - 00000062 _____ () C:\Users\sebastian\AppData\Roaming\sp_data.sys
2014-06-28 22:03 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-28 22:02 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-06-28 22:01 - 2014-06-28 22:00 - 00000000 ____D () C:\AdwCleaner
2014-06-28 22:01 - 2014-04-03 18:48 - 00000000 ____D () C:\Users\sebastian
2014-06-28 22:00 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-06-28 21:59 - 2014-06-28 21:59 - 01342659 _____ () C:\Users\sebastian\Downloads\adwcleaner_3.213.exe
2014-06-28 21:58 - 2014-06-28 21:58 - 00022488 _____ () C:\Users\sebastian\Desktop\mbam.txt
2014-06-28 21:54 - 2012-07-26 10:18 - 00000000 ____D () C:\Windows\DigitalLocker
2014-06-28 21:50 - 2014-05-01 08:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-28 21:38 - 2014-06-28 21:38 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-28 21:38 - 2014-06-28 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-28 21:37 - 2014-06-28 21:37 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-28 21:37 - 2014-06-28 21:36 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\sebastian\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-27 17:28 - 2014-06-27 17:28 - 00015085 _____ () C:\ComboFix.txt
2014-06-27 17:28 - 2014-06-27 17:20 - 00000000 ____D () C:\Qoobox
2014-06-27 17:28 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-06-27 17:26 - 2014-06-27 17:19 - 00000000 ____D () C:\Windows\erdnt
2014-06-27 17:26 - 2012-07-26 07:26 - 00000215 _____ () C:\Windows\system.ini
2014-06-27 17:14 - 2014-06-27 17:14 - 05212118 ____R (Swearware) C:\Users\sebastian\Downloads\ComboFix.exe
2014-06-27 17:04 - 2012-07-26 09:59 - 00000000 ____D () C:\Windows\CbsTemp
2014-06-27 16:45 - 2014-06-27 16:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\sebastian\Downloads\revosetup95.exe
2014-06-27 16:45 - 2014-06-27 16:45 - 00001226 _____ () C:\Users\sebastian\Desktop\Revo Uninstaller.lnk
2014-06-27 16:45 - 2014-06-27 16:45 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-27 16:44 - 2013-11-22 15:48 - 00003474 _____ () C:\Windows\System32\Tasks\ASUS Live Update1
2014-06-27 16:44 - 2013-11-22 15:48 - 00003464 _____ () C:\Windows\System32\Tasks\ASUS Live Update2
2014-06-26 17:32 - 2014-06-26 17:32 - 00001121 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00001109 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-06-26 17:32 - 2014-06-26 17:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-26 14:33 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-06-26 14:22 - 2014-04-03 18:58 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-398813873-3760832578-3833595727-1002
2014-06-26 13:55 - 2014-06-26 13:48 - 00000000 ____D () C:\ProgramData\Reimage Express
2014-06-26 13:39 - 2014-06-26 13:37 - 00000163 _____ () C:\Windows\Reimage.ini
2014-06-26 13:39 - 2014-06-19 14:29 - 00000000 ____D () C:\ProgramData\CDB
2014-06-26 12:56 - 2014-04-04 04:58 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-26 12:55 - 2014-04-04 04:58 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-06-26 12:32 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-06-26 12:32 - 2012-07-26 07:38 - 00000000 ____D () C:\Windows\system32\Sysprep
2014-06-26 12:31 - 2013-11-22 15:46 - 00000000 ____D () C:\ProgramData\P4G
2014-06-26 12:30 - 2013-04-26 01:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2014-06-26 12:29 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-06-26 12:27 - 2014-06-19 14:21 - 00000000 ____D () C:\ProgramData\f25cb3e6521ce1d6
2014-06-26 12:24 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\registration
2014-06-24 19:59 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-06-19 17:33 - 2014-06-19 17:33 - 00000000 ____D () C:\ProgramData\ASUS
2014-06-19 16:04 - 2014-06-19 16:04 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\UpdatusUser\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\sebastian\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Gast
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Google
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Comodo
2014-06-19 14:21 - 2014-06-19 14:21 - 00000000 ____D () C:\Users\Administrator
2014-06-19 09:42 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-31 07:16 - 2014-04-06 15:42 - 00703992 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-31 07:16 - 2014-04-06 15:42 - 00105464 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
Some content of TEMP:
====================
C:\Users\sebastian\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-24 19:53
==================== End Of Log ============================ --- --- --- |