Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 03.09.2014 13:56:00, SYSTEM, ICH-PC, Protection, Malware Protection, Starting,
Protection, 03.09.2014 13:56:00, SYSTEM, ICH-PC, Protection, Malware Protection, Started,
Protection, 03.09.2014 13:56:00, SYSTEM, ICH-PC, Protection, Malicious Website Protection, Starting,
Protection, 03.09.2014 13:56:03, SYSTEM, ICH-PC, Protection, Malicious Website Protection, Started,
Update, 03.09.2014 13:56:25, SYSTEM, ICH-PC, Manual, Rootkit Database, 2014.2.20.1, 2014.8.21.1,
Update, 03.09.2014 13:56:40, SYSTEM, ICH-PC, Manual, Malware Database, 2014.3.4.9, 2014.9.3.3,
(end)
# AdwCleaner v3.309 - Bericht erstellt am 03/09/2014 um 14:28:36
# Aktualisiert 02/09/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Premium (32 bits)
# Benutzername : Ich - ICH-PC
# Gestartet von : C:\Users\Ich\Downloads\adwcleaner_3.309.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gefunden : C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
Datei Gefunden : C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\foxydeal.sqlite
Datei Gefunden : C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\invalidprefs.js
Ordner Gefunden : C:\Program Files\Gemeinsame Dateien
Ordner Gefunden : C:\Users\Ich\AppData\Local\Smartbar
Ordner Gefunden : C:\Users\Ich\AppData\LocalLow\Smartbar
Ordner Gefunden : C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmootherWeb
Ordner Gefunden : C:\Users\Ich\AppData\Roaming\OpenCandy
Ordner Gefunden : C:\Users\Ich\AppData\Roaming\SmootherWeb
***** [ Tasks ] *****
Task Gefunden : BitGuard
Task Gefunden : EPUpdater
Task Gefunden : LyricXeeker Update
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gefunden : HKCU\Software\Optimizer Pro
Schlüssel Gefunden : HKLM\SOFTWARE\AdvertisingSupport
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\AppID\{9DC8FA51-B596-4F77-802C-5B295919C205}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{3E28F712-0D6C-4EE3-AC8C-8F060F5D7C33}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{533403E2-6E21-4615-9E28-43F4E97E977B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6CE321DA-DC11-45C6-A0FC-4E8A7D978ABC}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{6EEBC7FF-67DA-4B90-9251-C2C5696E4B48}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{74137531-80F7-406F-9543-7D11385FA8C8}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{832599B2-55BF-4437-8F3E-030CF5AEB262}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{9B7B034B-944A-4261-B487-862F642F7615}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{B1A429DB-FB06-4645-B7C0-0CC405EAD3CD}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{DD67706E-819E-4EBD-BF8D-6D6147CC7A49}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{0FCE4F01-64EC-42F1-83E1-1E08D38605D2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{1A2A195A-A0F9-4006-AF02-3F05EEFDE792}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{22511E2E-7970-414E-BC7C-28D16C4AF54D}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{23C5311E-016D-4999-BCB1-499898429D6C}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2C4B6DB8-6413-403B-A038-16A352CFE8B9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{2D9DB233-DC4B-4677-946C-5FA5ABCF506B}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{46803190-228D-470E-90FE-F5E0CEA9C4F2}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{5180FE16-2E09-497B-9C8B-5A6F029ECECB}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{A4F6E1B3-469E-46EF-A936-FBA9D5EFD2B9}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{C97AF157-6A27-4F57-9D47-E2D3E4761B77}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{ED0D2C81-7DB5-4599-B7C0-1033418B5672}
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\PCProxy.DataContainer
Schlüssel Gefunden : HKLM\SOFTWARE\Classes\TypeLib\{ED721A76-8160-4DA0-A18E-7FD7C4574774}
Schlüssel Gefunden : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gefunden : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gefunden : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WindowsMangerProtect
Wert Gefunden : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [smoother]
Wert Gefunden : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs]
***** [ Browser ] *****
-\\ Internet Explorer v8.0.6001.18702
-\\ Mozilla Firefox v31.0 (x86 de)
[ Datei : C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\prefs.js ]
Zeile gefunden : user_pref("extensions.helperbar.DockingPositionDown", false);
Zeile gefunden : user_pref("extensions.helperbar.SmartbarDisabled", false);
Zeile gefunden : user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Zeile gefunden : user_pref("extensions.helperbar.Visibility", false);
Zeile gefunden : user_pref("extensions.helperbar.keepAliveLastevent", "1409331772");
Zeile gefunden : user_pref("extensions.helperbar.lastExternalJsUpdate", "1409320777974");
*************************
AdwCleaner[R0].txt - [6473 octets] - [03/09/2014 14:16:30]
AdwCleaner[R1].txt - [6088 octets] - [03/09/2014 14:28:36]
AdwCleaner[S0].txt - [726 octets] - [03/09/2014 14:26:28]
Ich habe jetzt die Punkte unter adwcleaner abgearbeitet, dann folgte der erwünschte Neustart. LEider fährt mein Pc jetzt nicht mehr hoch, nach der Passworteingabe für meinen Benutzer wird der bildschirm schwarz und bleibt auch schwarz. schreibe jetzt hier im abgesicherten Modus. Was kann ich tun das ich wieder normal auf mein Pc zugreifen kann? Alles weitere wird jetzt im abgesicherten Modus durchgeführt.JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows Vista (TM) Home Premium x86
Ran by Ich on 03.09.2014 at 15:13:58,82
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\optimizer pro
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.bandobjectattribute
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.dockingpanel
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.iesmartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.iesmartbarbandobject
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.smartbardisplaystate
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\iesmartbar.smartbarmenuform
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Ich\AppData\Roaming\opencandy"
Successfully deleted: [Folder] "C:\Users\Ich\AppData\Roaming\thinstall"
Successfully deleted: [Folder] "C:\Users\Ich\appdata\locallow\smartbar"
~~~ FireFox
Successfully deleted: [File] C:\Users\Ich\AppData\Roaming\mozilla\firefox\profiles\p6x5vqq2.default\invalidprefs.js
Successfully deleted the following from C:\Users\Ich\AppData\Roaming\mozilla\firefox\profiles\p6x5vqq2.default\prefs.js
user_pref("extensions.helperbar.SmartbarDisabled", false);
user_pref("extensions.helperbar.SmartbarStateMinimaized", false);
Emptied folder: C:\Users\Ich\AppData\Roaming\mozilla\firefox\profiles\p6x5vqq2.default\minidumps [152 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.09.2014 at 15:16:03,79
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-09-2014
Ran by Ich (administrator) on ICH-PC on 03-09-2014 15:25:14
Running from C:\Users\Ich\Desktop
Platform: Microsoft® Windows Vista™ Home Premium (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8
Boot Mode: Safe Mode (with Networking)
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [LManager] => C:\Program Files\Launch Manager\QtZgAcer.EXE [817672 2008-06-04] (Dritek System Inc.)
HKLM\...\Run: [ZPdtWzdVitaKey MC3000] => C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe [3673600 2012-10-05] (Arachnoid Biometrics Identification Group Corp.)
HKLM\...\Run: [WinampAgent] => C:\Program Files\Winamp\winampa.exe [74752 2011-12-09] (Nullsoft, Inc.)
HKLM\...\Run: [NeroFilterCheck] => C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [153136 2007-02-26] (Nero AG)
HKLM\...\Run: [Smart File Advisor] => C:\Program Files\Smart File Advisor\sfa.exe [280824 2011-04-04] (Filefacts.net)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-14] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM\...\RunOnce: [FreeHideIPunstall] => [X]
Winlogon\Notify\AWinNotifyVitaKey MC3000: C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.)
HKU\S-1-5-21-3325081473-2881869368-4166051970-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125440 2006-11-02] (Microsoft Corporation)
HKU\S-1-5-21-3325081473-2881869368-4166051970-1000\...\Run: [smoother] => C:\Users\Ich\AppData\Roaming\SmootherWeb\SmootherWeb-Installer.exe [489603 2014-08-12] ()
HKU\S-1-5-21-3325081473-2881869368-4166051970-1000\...\Run: [CyberGhost] => C:\Program Files\CyberGhost 5\CyberGhost.EXE [404080 2014-06-12] (CyberGhost S.R.L.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyServer: http=;ftp=;https=;
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default
FF NewTab: www.google.de
FF Homepage: https://www.google.de/?gfe_rd=cr&ei=NPsFVOX3HqiF8QfCtYCgDQ&gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @java.com/DTPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.60.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: ProxTube - Unblock YouTube - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\ich@maltegoetz.de [2014-07-23]
FF Extension: YouTube Unblocker - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\youtubeunblocker@unblocker.yt [2014-07-05]
FF Extension: Smoother Web - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\jid1-U7omKQ6kQfxMaQ@jetpack.xpi [2014-08-28]
FF Extension: Tab Converter - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\{40f3666d-0746-451b-893f-6be81e8d1e33}.xpi [2014-07-12]
FF Extension: {519dc759-96fc-494f-8786-1ada2fcc4f8f} - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\{519dc759-96fc-494f-8786-1ada2fcc4f8f}.xpi [2014-07-06]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-22]
FF Extension: Adblock Plus - C:\Users\Ich\AppData\Roaming\Mozilla\Firefox\Profiles\p6x5vqq2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-10-10]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2012-10-28]
FF HKCU\...\Firefox\Extensions: [{60525b7e-56a2-4031-a4f4-35eb2c9dd4d8}] - C:\Program Files\LyriXeeker\130.xpi
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-14] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1021008 2014-08-14] (Avira Operations GmbH & Co. KG)
S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [64624 2014-06-12] (CyberGhost S.R.L)
S2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-08-19] () [File not signed]
S2 IGBASVC; C:\Program Files\Acer\Acer Bio Protection\BASVC.exe [3521024 2012-10-05] () [File not signed]
S2 libusbd; C:\Windows\System32\libusbd-nt.exe [18944 2005-03-09] (hxxp://libusb-win32.sourceforge.net) [File not signed]
S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 AlfaFF; C:\Windows\System32\Drivers\AlfaFF.sys [43184 2012-10-05] (Alfa Corporation)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [97648 2014-06-24] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-06-03] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-27] (Avira Operations GmbH & Co. KG)
S2 int15; C:\Windows\system32\drivers\int15.sys [69632 2007-01-26] () [File not signed]
S4 JRAID; C:\Windows\system32\drivers\jraid.sys [48640 2007-05-09] (JMicron Technology Corp.)
R3 L1E; C:\Windows\System32\DRIVERS\L1E60x86.sys [48640 2009-08-05] (Atheros Communications, Inc.)
R3 libusb0; C:\Windows\System32\drivers\libusb0.sys [33792 2005-03-09] () [File not signed]
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-09-03] (Malwarebytes Corporation)
S3 MotioninJoyXFilter; C:\Windows\System32\DRIVERS\MijXfilt.sys [99400 2012-05-12] (MotioninJoy)
S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-21] (Avira GmbH)
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R3 winbondcir; C:\Windows\System32\DRIVERS\winbondcir.sys [43008 2007-03-28] (Winbond Electronics Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [22016 2006-11-02] (Microsoft Corporation)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-03 15:25 - 2014-09-03 15:25 - 00001307 _____ () C:\Users\Ich\Desktop\FRST.txt
2014-09-03 15:25 - 2014-09-03 15:25 - 00000000 ____D () C:\Users\Ich\Desktop\FRST-OlderVersion
2014-09-03 15:19 - 2014-09-03 15:19 - 00000632 _____ () C:\Users\Ich\Desktop\JRT.txt
2014-09-03 15:13 - 2014-09-03 15:13 - 00000000 ____D () C:\Windows\ERUNT
2014-09-03 14:57 - 2014-09-03 14:57 - 01016261 _____ (Thisisu) C:\Users\Ich\Downloads\JRT.exe
2014-09-03 14:16 - 2014-09-03 14:29 - 00000000 ____D () C:\AdwCleaner
2014-09-03 14:15 - 2014-09-03 14:15 - 01370483 _____ () C:\Users\Ich\Downloads\adwcleaner_3.309.exe
2014-09-03 14:13 - 2014-09-03 14:13 - 00000646 _____ () C:\Users\Ich\Desktop\Malwarebytes.txt
2014-09-03 13:55 - 2014-09-03 15:12 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-03 13:55 - 2014-09-03 13:55 - 00000899 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-03 13:55 - 2014-09-03 13:55 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-03 13:55 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-09-03 13:55 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-09-03 13:55 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-03 13:54 - 2014-09-03 13:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ich\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-03 13:50 - 2014-09-03 13:50 - 00000000 ____D () C:\Users\Ich\AppData\Local\CyberGhost
2014-09-03 13:49 - 2014-09-03 13:49 - 00001720 _____ () C:\Users\Ich\Desktop\CyberGhost 5.lnk
2014-09-03 13:49 - 2014-09-03 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
2014-09-03 13:49 - 2014-09-03 13:49 - 00000000 ____D () C:\Program Files\TAP-Windows
2014-09-03 13:48 - 2014-09-03 13:49 - 08646824 _____ (CyberGhost S.R.L. ) C:\Users\Ich\Downloads\CG_5.0.13.17.exe
2014-09-02 20:10 - 2014-09-02 20:10 - 00009538 _____ () C:\ComboFix.txt
2014-09-02 20:00 - 2014-09-02 20:10 - 00000000 ____D () C:\ComboFix
2014-09-02 19:31 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-09-02 19:31 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-09-02 19:31 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-09-02 19:31 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-09-02 19:31 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-09-02 19:31 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-09-02 19:31 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-09-02 19:31 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-09-02 19:31 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-09-02 19:30 - 2014-09-02 20:10 - 00000000 ____D () C:\Qoobox
2014-09-02 19:30 - 2014-09-02 19:47 - 00000000 ____D () C:\Windows\erdnt
2014-09-02 19:29 - 2014-09-02 19:55 - 05576326 ____R (Swearware) C:\Users\Ich\Downloads\ComboFix.exe
2014-09-02 15:33 - 2014-09-02 15:33 - 00001057 _____ () C:\Users\Ich\Desktop\Revo Uninstaller.lnk
2014-09-02 15:33 - 2014-09-02 15:33 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-09-02 15:32 - 2014-09-02 15:33 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Ich\Downloads\revosetup95.exe
2014-08-31 19:31 - 2014-09-03 15:25 - 00000000 ____D () C:\FRST
2014-08-30 03:22 - 2014-09-03 15:25 - 01096704 _____ (Farbar) C:\Users\Ich\Desktop\FRST.exe
2014-08-29 17:47 - 2014-08-29 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-08-29 17:47 - 2006-10-26 19:56 - 00032592 _____ (Microsoft Corporation) C:\Windows\system32\msonpmon.dll
2014-08-29 17:45 - 2014-08-29 17:45 - 00000000 ____D () C:\Program Files\Microsoft Works
2014-08-29 17:44 - 2014-08-29 17:44 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio
2014-08-29 17:44 - 2014-08-29 17:44 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-08-29 17:43 - 2014-08-29 17:43 - 00000000 ____D () C:\Windows\PCHEALTH
2014-08-29 17:41 - 2014-08-29 17:41 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8
2014-08-29 17:39 - 2014-08-29 17:47 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-29 17:39 - 2014-08-29 17:44 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-08-29 17:39 - 2014-08-29 17:39 - 00000000 ___RD () C:\MSOCache
2014-08-29 17:39 - 2014-08-29 17:39 - 00000000 ____D () C:\Users\Ich\AppData\Local\Microsoft Help
2014-08-29 17:12 - 2014-08-29 17:12 - 00139488 _____ () C:\Windows\system32\XMLOperations.xml
2014-08-28 15:02 - 2014-08-28 15:02 - 00000049 _____ () C:\Windows\NeroDigital.ini
2014-08-28 05:51 - 2014-08-28 05:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-28 04:29 - 2014-08-28 05:50 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
2014-08-28 04:29 - 2014-08-28 04:29 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-08-28 04:29 - 2014-08-28 04:29 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-08-28 04:07 - 2014-08-28 04:07 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmootherWeb
2014-08-28 04:06 - 2014-09-03 14:26 - 00000000 ____D () C:\Users\Ich\AppData\Local\Smartbar
2014-08-28 04:06 - 2014-08-28 15:42 - 00001810 _____ () C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-28 04:06 - 2014-08-28 04:20 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\SmootherWeb
2014-08-27 19:00 - 2010-03-05 16:01 - 00420352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-27 19:00 - 2009-12-04 09:19 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-08-27 16:27 - 2009-03-08 23:09 - 00391536 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-27 16:27 - 2009-03-08 13:41 - 05937152 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-27 16:27 - 2009-03-08 13:39 - 11063808 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-27 16:27 - 2009-03-08 13:35 - 00385024 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-08-27 16:27 - 2009-03-08 13:34 - 01469440 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-27 16:27 - 2009-03-08 13:34 - 01206784 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-27 16:27 - 2009-03-08 13:34 - 00914944 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-27 16:27 - 2009-03-08 13:34 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-08-27 16:27 - 2009-03-08 13:34 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\WinFXDocObj.exe
2014-08-27 16:27 - 2009-03-08 13:34 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-27 16:27 - 2009-03-08 13:34 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-08-27 16:27 - 2009-03-08 13:34 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-08-27 16:27 - 2009-03-08 13:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-08-27 16:27 - 2009-03-08 13:33 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\ieaksie.dll
2014-08-27 16:27 - 2009-03-08 13:33 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-27 16:27 - 2009-03-08 13:33 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\ieakeng.dll
2014-08-27 16:27 - 2009-03-08 13:33 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\PDMSetup.exe
2014-08-27 16:27 - 2009-03-08 13:33 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-08-27 16:27 - 2009-03-08 13:33 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-08-27 16:27 - 2009-03-08 13:33 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-08-27 16:27 - 2009-03-08 13:33 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-27 16:27 - 2009-03-08 13:33 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\corpol.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 01985024 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00611840 _____ (Microsoft Corporation) C:\Windows\system32\mstime.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00594432 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-27 16:27 - 2009-03-08 13:32 - 00169472 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-08-27 16:27 - 2009-03-08 13:32 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\ieakui.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\advpack.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\admparse.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-27 16:27 - 2009-03-08 13:32 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-08-27 16:27 - 2009-03-08 13:32 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 01638912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-27 16:27 - 2009-03-08 13:31 - 00348160 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00183808 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-08-27 16:27 - 2009-03-08 13:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-08-27 16:27 - 2009-03-08 13:31 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-08-27 16:27 - 2009-03-08 13:30 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-08-27 16:27 - 2009-03-08 13:22 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-08-27 16:27 - 2009-03-08 13:22 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-08-27 16:27 - 2009-03-08 13:11 - 00445952 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-27 16:27 - 2009-02-07 06:07 - 03698584 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-08-27 16:26 - 2014-08-27 16:42 - 00058468 _____ () C:\Windows\ie8_main.log
2014-08-27 16:23 - 2014-09-03 13:50 - 00000000 ____D () C:\Program Files\CyberGhost 5
2014-08-27 16:16 - 2014-08-27 16:16 - 00000016 _____ () C:\Windows\system32\PCProxyOff.ini
2014-08-27 16:15 - 2014-08-27 16:15 - 00073728 _____ () C:\Windows\system32\VistaInfo32.dll
2014-08-27 16:15 - 2014-08-27 16:15 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\SpOrder.dll
2014-08-27 15:59 - 2014-08-27 15:59 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\JonDo
2014-08-23 03:40 - 2014-08-23 03:40 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\OpenOffice
2014-08-23 03:21 - 2014-08-23 03:25 - 164858324 _____ () C:\Users\Ich\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe
2014-08-21 17:41 - 2014-08-21 17:41 - 00000000 ____D () C:\Users\Ich\AppData\Local\Adobe
2014-08-16 16:33 - 2014-08-16 16:33 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\NVIDIA
2014-08-08 00:44 - 2014-08-08 00:50 - 209830343 _____ () C:\Users\Ich\Downloads\[AKA] One Piece 403 [x264,720p][10E69A2B].mkv
2014-08-06 19:07 - 2014-08-06 19:07 - 00000000 ____D () C:\Users\Ich\AppData\Local\TuneUp Software
2014-08-06 19:05 - 2014-08-06 19:07 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2014
2014-08-06 19:01 - 2014-08-06 19:02 - 26626552 _____ (DVDVideoSoft Ltd. ) C:\Users\Ich\Downloads\FreeVideoEditor.exe
2014-08-06 18:58 - 2014-08-06 18:58 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\AVS4YOU
2014-08-06 18:57 - 2014-08-06 19:01 - 00000000 ____D () C:\Program Files\Common Files\AVSMedia
2014-08-06 18:57 - 2014-08-06 19:01 - 00000000 ____D () C:\Program Files\AVS4YOU
2014-08-06 18:57 - 2014-08-06 18:58 - 00000000 ____D () C:\ProgramData\AVS4YOU
2014-08-06 18:57 - 2012-03-23 19:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\msxml3a.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-03 15:25 - 2014-09-03 15:25 - 00001307 _____ () C:\Users\Ich\Desktop\FRST.txt
2014-09-03 15:25 - 2014-09-03 15:25 - 00000000 ____D () C:\Users\Ich\Desktop\FRST-OlderVersion
2014-09-03 15:25 - 2014-08-31 19:31 - 00000000 ____D () C:\FRST
2014-09-03 15:25 - 2014-08-30 03:22 - 01096704 _____ (Farbar) C:\Users\Ich\Desktop\FRST.exe
2014-09-03 15:19 - 2014-09-03 15:19 - 00000632 _____ () C:\Users\Ich\Desktop\JRT.txt
2014-09-03 15:13 - 2014-09-03 15:13 - 00000000 ____D () C:\Windows\ERUNT
2014-09-03 15:12 - 2014-09-03 13:55 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-09-03 15:11 - 2006-11-02 12:33 - 00810610 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-03 14:59 - 2012-10-06 00:25 - 00001088 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-03 14:59 - 2006-11-02 15:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-09-03 14:59 - 2006-11-02 14:47 - 00005072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-09-03 14:59 - 2006-11-02 14:47 - 00005072 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-09-03 14:57 - 2014-09-03 14:57 - 01016261 _____ (Thisisu) C:\Users\Ich\Downloads\JRT.exe
2014-09-03 14:53 - 2012-10-06 04:20 - 00082770 _____ () C:\Windows\PFRO.log
2014-09-03 14:48 - 2006-11-02 15:01 - 00032638 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-03 14:43 - 2014-01-24 20:14 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-09-03 14:43 - 2006-11-02 14:52 - 01744238 _____ () C:\Windows\WindowsUpdate.log
2014-09-03 14:29 - 2014-09-03 14:16 - 00000000 ____D () C:\AdwCleaner
2014-09-03 14:26 - 2014-08-28 04:06 - 00000000 ____D () C:\Users\Ich\AppData\Local\Smartbar
2014-09-03 14:19 - 2012-10-06 00:25 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-03 14:15 - 2014-09-03 14:15 - 01370483 _____ () C:\Users\Ich\Downloads\adwcleaner_3.309.exe
2014-09-03 14:13 - 2014-09-03 14:13 - 00000646 _____ () C:\Users\Ich\Desktop\Malwarebytes.txt
2014-09-03 13:55 - 2014-09-03 13:55 - 00000899 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-09-03 13:55 - 2014-09-03 13:55 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-09-03 13:54 - 2014-09-03 13:54 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Ich\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-03 13:50 - 2014-09-03 13:50 - 00000000 ____D () C:\Users\Ich\AppData\Local\CyberGhost
2014-09-03 13:50 - 2014-08-27 16:23 - 00000000 ____D () C:\Program Files\CyberGhost 5
2014-09-03 13:49 - 2014-09-03 13:49 - 00001720 _____ () C:\Users\Ich\Desktop\CyberGhost 5.lnk
2014-09-03 13:49 - 2014-09-03 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberGhost 5
2014-09-03 13:49 - 2014-09-03 13:49 - 00000000 ____D () C:\Program Files\TAP-Windows
2014-09-03 13:49 - 2014-09-03 13:48 - 08646824 _____ (CyberGhost S.R.L. ) C:\Users\Ich\Downloads\CG_5.0.13.17.exe
2014-09-02 20:10 - 2014-09-02 20:10 - 00009538 _____ () C:\ComboFix.txt
2014-09-02 20:10 - 2014-09-02 20:00 - 00000000 ____D () C:\ComboFix
2014-09-02 20:10 - 2014-09-02 19:30 - 00000000 ____D () C:\Qoobox
2014-09-02 20:08 - 2006-11-02 12:23 - 00000215 _____ () C:\Windows\system.ini
2014-09-02 19:55 - 2014-09-02 19:29 - 05576326 ____R (Swearware) C:\Users\Ich\Downloads\ComboFix.exe
2014-09-02 19:49 - 2006-11-02 13:18 - 00000000 __RHD () C:\Users\Default
2014-09-02 19:49 - 2006-11-02 13:18 - 00000000 ___RD () C:\Users\Public
2014-09-02 19:47 - 2014-09-02 19:30 - 00000000 ____D () C:\Windows\erdnt
2014-09-02 19:42 - 2006-11-02 12:22 - 38010880 _____ () C:\Windows\system32\config\SOFTWARE.bak
2014-09-02 19:42 - 2006-11-02 12:22 - 25427968 _____ () C:\Windows\system32\config\COMPON~1.bak
2014-09-02 19:42 - 2006-11-02 12:22 - 20709376 _____ () C:\Windows\system32\config\SYSTEM.bak
2014-09-02 19:42 - 2006-11-02 12:22 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak
2014-09-02 19:42 - 2006-11-02 12:22 - 00262144 _____ () C:\Windows\system32\config\SAM.bak
2014-09-02 19:42 - 2006-11-02 12:22 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak
2014-09-02 15:33 - 2014-09-02 15:33 - 00001057 _____ () C:\Users\Ich\Desktop\Revo Uninstaller.lnk
2014-09-02 15:33 - 2014-09-02 15:33 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-09-02 15:33 - 2014-09-02 15:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Ich\Downloads\revosetup95.exe
2014-08-30 18:17 - 2012-10-28 17:56 - 00000000 ____D () C:\Users\Ich\Desktop\Controller - Gamepad
2014-08-29 18:13 - 2012-10-05 21:13 - 00100432 _____ () C:\Users\Ich\AppData\Local\GDIPFONTCACHEV1.DAT
2014-08-29 18:12 - 2006-11-02 14:47 - 00374776 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-29 17:47 - 2014-08-29 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2014-08-29 17:47 - 2014-08-29 17:39 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-29 17:45 - 2014-08-29 17:45 - 00000000 ____D () C:\Program Files\Microsoft Works
2014-08-29 17:45 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-08-29 17:44 - 2014-08-29 17:44 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio
2014-08-29 17:44 - 2014-08-29 17:44 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-08-29 17:44 - 2014-08-29 17:39 - 00000000 ____D () C:\Program Files\Microsoft Office
2014-08-29 17:44 - 2006-11-02 14:37 - 00000000 ____D () C:\Windows\ShellNew
2014-08-29 17:44 - 2006-11-02 14:37 - 00000000 ____D () C:\Program Files\MSBuild
2014-08-29 17:43 - 2014-08-29 17:43 - 00000000 ____D () C:\Windows\PCHEALTH
2014-08-29 17:43 - 2012-10-27 17:28 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-08-29 17:41 - 2014-08-29 17:41 - 00000000 ____D () C:\Program Files\Microsoft Visual Studio 8
2014-08-29 17:40 - 2006-11-02 13:18 - 00000000 ____D () C:\Program Files\Common Files\System
2014-08-29 17:40 - 2006-11-02 12:23 - 00000219 _____ () C:\Windows\win.ini
2014-08-29 17:39 - 2014-08-29 17:39 - 00000000 ___RD () C:\MSOCache
2014-08-29 17:39 - 2014-08-29 17:39 - 00000000 ____D () C:\Users\Ich\AppData\Local\Microsoft Help
2014-08-29 17:12 - 2014-08-29 17:12 - 00139488 _____ () C:\Windows\system32\XMLOperations.xml
2014-08-28 15:48 - 2013-06-20 21:02 - 00000122 _____ () C:\Users\Ich\Desktop\TOP 20 Deutsche Single Charts April 2013 - YouTube.URL
2014-08-28 15:48 - 2013-06-20 21:02 - 00000122 _____ () C:\Users\Ich\Desktop\Top 20 Deutsche Charts Mai 2013 - YouTube.URL
2014-08-28 15:42 - 2014-08-28 04:06 - 00001810 _____ () C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-08-28 15:42 - 2012-10-05 23:12 - 00000858 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-08-28 15:42 - 2012-10-05 21:13 - 00000949 _____ () C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-08-28 15:02 - 2014-08-28 15:02 - 00000049 _____ () C:\Windows\NeroDigital.ini
2014-08-28 05:51 - 2014-08-28 05:51 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-28 05:50 - 2014-08-28 04:29 - 00000000 ____D () C:\Windows\455F074C814E4520B69B5584BD90400C.TMP
2014-08-28 04:29 - 2014-08-28 04:29 - 00000000 ____D () C:\Program Files\Enigma Software Group
2014-08-28 04:29 - 2014-08-28 04:29 - 00000000 ____D () C:\Program Files\Common Files\Wise Installation Wizard
2014-08-28 04:20 - 2014-08-28 04:06 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\SmootherWeb
2014-08-28 04:07 - 2014-08-28 04:07 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmootherWeb
2014-08-27 18:07 - 2006-11-02 13:18 - 00000000 ____D () C:\Windows\system32\de-DE
2014-08-27 16:42 - 2014-08-27 16:26 - 00058468 _____ () C:\Windows\ie8_main.log
2014-08-27 16:16 - 2014-08-27 16:16 - 00000016 _____ () C:\Windows\system32\PCProxyOff.ini
2014-08-27 16:15 - 2014-08-27 16:15 - 00073728 _____ () C:\Windows\system32\VistaInfo32.dll
2014-08-27 16:15 - 2014-08-27 16:15 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\SpOrder.dll
2014-08-27 15:59 - 2014-08-27 15:59 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\JonDo
2014-08-24 17:57 - 2012-10-06 00:14 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\Winamp
2014-08-24 03:19 - 2012-10-06 03:58 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\vlc
2014-08-23 03:40 - 2014-08-23 03:40 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\OpenOffice
2014-08-23 03:25 - 2014-08-23 03:21 - 164858324 _____ () C:\Users\Ich\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe
2014-08-23 03:25 - 2012-09-04 15:31 - 00000000 ____D () C:\Users\Ich\Desktop\Dwb projekte
2014-08-23 03:24 - 2012-10-06 03:59 - 00037888 _____ () C:\Users\Ich\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-08-21 17:41 - 2014-08-21 17:41 - 00000000 ____D () C:\Users\Ich\AppData\Local\Adobe
2014-08-17 15:29 - 2014-06-20 12:51 - 00000000 ____D () C:\Users\Ich\Desktop\Handyvertrag
2014-08-16 16:33 - 2014-08-16 16:33 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\NVIDIA
2014-08-12 20:58 - 2013-07-13 04:27 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-12 20:56 - 2006-11-02 12:24 - 96303304 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-08-08 00:50 - 2014-08-08 00:44 - 209830343 _____ () C:\Users\Ich\Downloads\[AKA] One Piece 403 [x264,720p][10E69A2B].mkv
2014-08-06 19:07 - 2014-08-06 19:07 - 00000000 ____D () C:\Users\Ich\AppData\Local\TuneUp Software
2014-08-06 19:07 - 2014-08-06 19:05 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2014
2014-08-06 19:04 - 2013-09-27 18:25 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-08-06 19:04 - 2012-11-01 18:22 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\DVDVideoSoft
2014-08-06 19:03 - 2013-08-19 13:55 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2014-08-06 19:03 - 2013-08-19 13:55 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-08-06 19:03 - 2012-11-01 18:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-08-06 19:02 - 2014-08-06 19:01 - 26626552 _____ (DVDVideoSoft Ltd. ) C:\Users\Ich\Downloads\FreeVideoEditor.exe
2014-08-06 19:01 - 2014-08-06 18:57 - 00000000 ____D () C:\Program Files\Common Files\AVSMedia
2014-08-06 19:01 - 2014-08-06 18:57 - 00000000 ____D () C:\Program Files\AVS4YOU
2014-08-06 18:58 - 2014-08-06 18:58 - 00000000 ____D () C:\Users\Ich\AppData\Roaming\AVS4YOU
2014-08-06 18:58 - 2014-08-06 18:57 - 00000000 ____D () C:\ProgramData\AVS4YOU
2014-08-04 12:45 - 2012-09-04 21:50 - 00000000 ____D () C:\temp
Some content of TEMP:
====================
C:\Users\Ich\AppData\Local\temp\avgnt.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-03 15:21
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---