BlackLambkin | 06.02.2015 17:18 | Okay, hier bitte:
1. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malware Protection, Starting,
Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malware Protection, Started,
Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting,
Update, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Manual, Remediation Database, 2013.10.16.1, 2014.12.6.1,
Update, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Manual, Rootkit Database, 2014.11.18.1, 2015.2.3.1,
Protection, 06.02.2015 16:37:14, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started,
Update, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Manual, Malware Database, 2014.11.20.6, 2015.2.6.4,
Protection, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Protection, Refresh, Starting,
Protection, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopping,
Protection, 06.02.2015 16:37:20, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopped,
Protection, 06.02.2015 16:37:26, SYSTEM, JULIA-PC, Protection, Refresh, Success,
Protection, 06.02.2015 16:37:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting,
Protection, 06.02.2015 16:37:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started,
Update, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Scheduler, Malware Database, 2015.2.6.4, 2015.2.6.5,
Protection, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Protection, Refresh, Starting,
Protection, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopping,
Protection, 06.02.2015 16:39:26, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Stopped,
Protection, 06.02.2015 16:39:33, SYSTEM, JULIA-PC, Protection, Refresh, Success,
Protection, 06.02.2015 16:39:33, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting,
Protection, 06.02.2015 16:39:33, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started,
Scan, 06.02.2015 16:47:11, SYSTEM, JULIA-PC, Manual, Start: % 1 "% 2", Dauer: % 1 min 8 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 9-Malwareerkennung,
Protection, 06.02.2015 16:48:13, SYSTEM, JULIA-PC, Protection, Malware Protection, Starting,
Protection, 06.02.2015 16:48:13, SYSTEM, JULIA-PC, Protection, Malware Protection, Started,
Protection, 06.02.2015 16:48:13, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Starting,
Protection, 06.02.2015 16:49:55, SYSTEM, JULIA-PC, Protection, Malicious Website Protection, Started,
(end) 2. Code:
# AdwCleaner v4.110 - Bericht erstellt 06/02/2015 um 16:57:32
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-05.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : julia - JULIA-PC
# Gestarted von : C:\Users\julia\Downloads\AdwCleaner_4.110.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\julia\AppData\Roaming\RHEng
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Daten Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings [ProxyOverride] - *.local
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Google Chrome v40.0.2214.111
*************************
AdwCleaner[R0].txt - [1308 Bytes] - [06/02/2015 16:55:03]
AdwCleaner[S0].txt - [1230 Bytes] - [06/02/2015 16:57:32]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1289 Bytes] ########## 3. Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 7 Home Premium x64
Ran by julia on 06.02.2015 at 17:03:48,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.02.2015 at 17:08:01,41
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 4.
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2015
Ran by julia (administrator) on JULIA-PC on 06-02-2015 17:11:16
Running from C:\Users\julia\Downloads
Loaded Profiles: julia (Available profiles: julia)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Corsair) C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.exe
(AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(X10) C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Sony) C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
() C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Wacom Technology, Corp.) C:\Program Files\WTouch\WTouchUser.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.25.11\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup_internetsecuritysuite.exe
(Thisisu) C:\Users\julia\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\julia\Downloads\FRST64 (3).exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1814312 2009-08-14] (Synaptics Incorporated)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3838800 2014-12-13] (LogMeIn Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2015-01-19] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-11-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1140688 2015-01-16] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466144 2014-11-27] (Sony)
HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30873192 2014-12-11] (Skype Technologies S.A.)
Startup: C:\Users\julia\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Deskjet 3050A J611 series.lnk -> C:\Program Files\HP\HP Deskjet 3050A J611 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3165034952-4008388936-3891106506-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @wacom.com/wacom-plugin,version=1.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovi.com/?gd=&ctid=CT3322288&octid=EB_ORIGINAL_CTID&ISID=M8A738E8B-DA80-4CDC-ACA0-AE9E423A9290&SearchSource=55&CUI=&UM=8&UP=SPE0DF30FF-D716-44B8-B619-581937559E07&SSPV=
CHR StartupUrls: Default -> "https://www.google.at/"
CHR Profile: C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-20]
CHR Extension: (Google Drive) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-20]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-07]
CHR Extension: (YouTube) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-20]
CHR Extension: (Google-Suche) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-20]
CHR Extension: (Avira SafeSearch) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\eglgfnfolcgijipffhlhbbnefdcbjbml [2015-02-03]
CHR Extension: (Google Wallet) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-20]
CHR Extension: (Quilt) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofholagheebdhalaonjopcfcedggjooo [2014-05-30]
CHR Extension: (Google Mail) - C:\Users\julia\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-20]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [807672 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-11-24] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [993584 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [865744 2015-01-16] (AVG Technologies CZ, s.r.o.)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [182520 2015-01-19] (Avira Operations GmbH & Co. KG)
R2 CorsairSSDToolBox; C:\Program Files (x86)\Corsair SSD Toolbox\CSSDTService.exe [1845864 2014-02-12] (Corsair)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2014-12-02] (LogMeIn, Inc.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2604344 2015-01-30] (AVG Technologies)
S3 TunngleService; C:\Program Files (x86)\Tunngle\TnglCtrl.exe [762320 2015-01-17] (Tunngle.net GmbH)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [44856 2015-01-30] (AVG Technologies)
R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [36664 2015-01-30] (AVG Technologies)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTouchService; C:\Program Files\WTouch\WTouchService.exe [127784 2009-11-24] (Wacom Technology, Corp.)
R2 x10nets; C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe [20480 2009-11-07] (X10) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-24] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\System32\DRIVERS\avnetflt.sys [43064 2014-11-24] (Avira Operations GmbH & Co. KG)
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-08-18] (Sony Mobile Communications)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-06] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
S3 RSUSBSTOR; C:\Windows\SysWOW64\Drivers\RtsUStor.sys [225280 2009-09-22] (Realtek Semiconductor Corp.)
R3 tap0901t; C:\Windows\System32\DRIVERS\tap0901t.sys [31232 2009-09-16] (Tunngle.net)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-11-24] (TuneUp Software)
R3 X10Hid; C:\Windows\System32\Drivers\x10hid.sys [15896 2009-05-13] (X10 Wireless Technology, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-06 17:10 - 2015-02-06 17:11 - 02131968 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (3).exe
2015-02-06 17:08 - 2015-02-06 17:08 - 00000625 _____ () C:\Users\julia\Desktop\JRT.txt
2015-02-06 17:03 - 2015-02-06 17:03 - 01388274 _____ (Thisisu) C:\Users\julia\Downloads\JRT.exe
2015-02-06 16:54 - 2015-02-06 16:57 - 00000000 ____D () C:\AdwCleaner
2015-02-06 16:54 - 2015-02-06 16:54 - 02112512 _____ () C:\Users\julia\Downloads\AdwCleaner_4.110.exe
2015-02-06 16:53 - 2015-02-06 16:53 - 00002612 _____ () C:\Users\julia\Desktop\mbam.txt
2015-02-06 16:37 - 2015-02-06 17:01 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-06 16:36 - 2015-02-06 16:36 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-06 16:36 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-06 16:36 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-06 16:36 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-06 16:35 - 2015-02-06 16:35 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\julia\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-06 16:34 - 2015-01-30 17:22 - 00044856 _____ (AVG Technologies) C:\Windows\system32\uxtuneup.dll
2015-02-06 16:34 - 2015-01-30 17:22 - 00036664 _____ (AVG Technologies) C:\Windows\SysWOW64\uxtuneup.dll
2015-02-05 20:08 - 2015-02-05 20:08 - 00002762 _____ () C:\Windows\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013
2015-02-04 16:30 - 2015-02-04 16:30 - 00000000 _____ () C:\Windows\setuperr.log
2015-02-04 14:22 - 2015-02-04 14:22 - 00002217 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015.lnk
2015-02-04 14:22 - 2015-02-04 14:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp 2015
2015-02-04 14:22 - 2015-01-30 17:23 - 00041784 _____ (AVG Technologies) C:\Windows\system32\TURegOpt.exe
2015-02-04 14:22 - 2015-01-30 17:22 - 00030520 _____ (AVG Technologies) C:\Windows\system32\authuitu.dll
2015-02-04 14:22 - 2015-01-30 17:22 - 00025912 _____ (AVG Technologies) C:\Windows\SysWOW64\authuitu.dll
2015-02-04 14:21 - 2015-02-04 14:21 - 00000932 _____ () C:\Users\Public\Desktop\AVG.lnk
2015-02-04 14:21 - 2015-02-04 14:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2015-02-04 14:20 - 2015-02-04 14:20 - 16634392 _____ (AVG Technologies) C:\Users\julia\Downloads\avg_gse_stb_all_445p1_105.exe
2015-02-03 20:12 - 2015-02-03 20:12 - 00019801 _____ () C:\ComboFix.txt
2015-02-03 20:10 - 2015-02-04 13:57 - 00000000 ____D () C:\Users\julia\AppData\Roaming\WTouch
2015-02-03 20:10 - 2015-02-03 20:10 - 00000000 ____D () C:\Users\julia\AppData\Local\AviraSpeedup
2015-02-03 20:04 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-02-03 20:04 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-02-03 20:04 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-02-03 20:04 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-02-03 20:04 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-02-03 20:04 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2015-02-03 20:04 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2015-02-03 20:04 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2015-02-03 20:00 - 2015-02-03 20:12 - 00000000 ____D () C:\Qoobox
2015-02-03 20:00 - 2015-02-03 20:11 - 00000000 ____D () C:\Windows\erdnt
2015-02-03 19:59 - 2015-02-03 19:59 - 05611380 ____R (Swearware) C:\Users\julia\Downloads\ComboFix.exe
2015-02-03 19:56 - 2015-02-03 19:56 - 00001268 _____ () C:\Users\julia\Desktop\Revo Uninstaller.lnk
2015-02-03 19:55 - 2015-02-03 19:55 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\julia\Downloads\revosetup95 (1).exe
2015-02-03 19:22 - 2015-02-03 19:22 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (2).exe
2015-02-03 18:48 - 2015-02-03 19:56 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-03 18:47 - 2015-02-03 18:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\julia\Downloads\revosetup95.exe
2015-02-03 18:43 - 2015-02-03 18:43 - 00003364 _____ () C:\Windows\System32\Tasks\AviraSpeedup
2015-02-03 18:43 - 2015-02-03 18:43 - 00001239 _____ () C:\Users\Public\Desktop\Avira System Speedup.lnk
2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Avira
2015-02-03 18:43 - 2015-02-03 18:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviraSpeedup
2015-02-03 18:42 - 2014-11-24 10:23 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-02-03 18:42 - 2014-11-24 10:23 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-02-03 18:42 - 2014-11-24 10:23 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-02-03 18:42 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-03 18:39 - 2015-02-03 18:42 - 00000000 ____D () C:\ProgramData\Avira
2015-02-03 18:39 - 2015-02-03 18:39 - 04515896 _____ (Avira Operations & Co. KG) C:\Users\julia\Downloads\avira_de_issuse_3002988189_7iomicq1hqlm0h0551hj_wd.exe
2015-02-03 18:39 - 2015-02-03 18:39 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-02-03 18:39 - 2015-02-03 18:39 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-03 18:30 - 2015-02-03 18:30 - 00025804 _____ () C:\Users\julia\Downloads\Addition.txt
2015-02-03 18:29 - 2015-02-06 17:11 - 00015121 _____ () C:\Users\julia\Downloads\FRST.txt
2015-02-03 18:29 - 2015-02-06 17:11 - 00000000 ____D () C:\FRST
2015-02-03 18:29 - 2015-02-03 18:29 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64 (1).exe
2015-02-02 20:10 - 2015-02-02 20:10 - 02131456 _____ (Farbar) C:\Users\julia\Downloads\FRST64.exe
2015-02-02 17:50 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Roaming\AVG
2015-02-02 17:48 - 2015-02-04 14:21 - 00000000 ____D () C:\ProgramData\Avg
2015-02-02 17:48 - 2015-02-04 14:21 - 00000000 ____D () C:\Program Files (x86)\AVG
2015-02-02 17:47 - 2015-02-04 14:21 - 00000000 ____D () C:\Users\julia\AppData\Local\AvgSetupLog
2015-02-02 17:47 - 2015-02-02 17:50 - 00000000 ____D () C:\Users\julia\AppData\Local\Avg
2015-02-02 17:47 - 2015-02-02 17:47 - 16634392 _____ (AVG Technologies) C:\Users\julia\Downloads\avg_gse_stb_all_445p1_143.exe
2015-02-01 12:34 - 2014-06-16 12:13 - 00043320 _____ (TuneUp Software) C:\Windows\system32\uxt5050.tmp
2015-02-01 12:33 - 2015-02-01 12:33 - 00000000 ____D () C:\Users\julia\AppData\Local\TuneUp Software
2015-02-01 12:32 - 2015-02-01 12:32 - 00001536 _____ () C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2015-02-01 12:32 - 2015-02-01 12:32 - 00001245 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2015-02-01 12:32 - 2015-02-01 12:32 - 00000238 _____ () C:\Users\julia\updhelper.xml
2015-02-01 12:32 - 2015-02-01 12:32 - 00000008 _____ () C:\Users\julia\updhelper.xml.lck
2015-02-01 12:32 - 2015-02-01 12:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-02-01 12:31 - 2015-02-01 12:32 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2015-02-01 12:31 - 2015-02-01 12:31 - 00000000 ____D () C:\Program Files (x86)\Free Codec Pack
2015-02-01 12:30 - 2015-02-01 12:30 - 34792128 _____ (DVDVideoSoft Ltd. ) C:\Users\julia\Downloads\FreeYouTubeToMP354Converter.exe
2015-01-24 18:12 - 2015-01-24 18:12 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline (1).exe
2015-01-24 18:08 - 2015-01-24 18:08 - 00343552 _____ (Microsoft) C:\Users\julia\Downloads\BA-ReDi4u_Offline.exe
2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Tunngle
2015-01-18 17:25 - 2015-01-18 19:26 - 00000000 ____D () C:\ProgramData\Tunngle
2015-01-18 17:25 - 2015-01-18 17:26 - 00000000 ____D () C:\Program Files (x86)\Tunngle
2015-01-18 17:25 - 2015-01-18 17:25 - 00000995 _____ () C:\Users\Public\Desktop\Tunngle.lnk
2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\Public\Documents\Tunngle
2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\Users\julia\Documents\Tunngle
2015-01-18 17:25 - 2015-01-18 17:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tunngle
2015-01-18 17:25 - 2009-09-16 07:02 - 00031232 _____ (Tunngle.net) C:\Windows\system32\Drivers\tap0901t.sys
2015-01-18 17:23 - 2015-01-18 17:23 - 04501720 _____ (Tunngle.net GmbH ) C:\Users\julia\Downloads\Tunngle_Setupv5.0.exe
2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-01-14 20:41 - 2015-01-14 20:41 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2015-01-14 20:30 - 2015-01-23 17:27 - 00000000 ____D () C:\Users\julia\AppData\Roaming\.minecraft
2015-01-14 20:30 - 2015-01-14 20:30 - 00000000 ____D () C:\Users\julia\AppData\Roaming\java
2015-01-14 20:29 - 2015-01-30 17:23 - 00000000 ____D () C:\Program Files (x86)\Minecraft
2015-01-14 20:29 - 2015-01-14 20:29 - 02318336 _____ () C:\Users\julia\Downloads\MinecraftInstaller.msi
2015-01-14 20:29 - 2015-01-14 20:29 - 00000961 _____ () C:\Users\Public\Desktop\Minecraft.lnk
2015-01-14 20:29 - 2015-01-14 20:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-01-14 16:29 - 2014-12-19 04:06 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 16:29 - 2014-12-19 02:46 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 16:29 - 2014-12-12 06:35 - 05553592 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-01-14 16:29 - 2014-12-12 06:31 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-01-14 16:29 - 2014-12-12 06:31 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-01-14 16:29 - 2014-12-12 06:31 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-01-14 16:29 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-01-14 16:29 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-01-14 16:29 - 2014-12-12 06:07 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-01-14 16:29 - 2014-12-11 18:47 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 16:29 - 2014-12-06 05:17 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 16:29 - 2014-12-06 04:50 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2015-01-14 16:29 - 2014-12-06 04:50 - 00052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-06 17:08 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-06 17:08 - 2009-07-14 05:45 - 00016304 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-06 17:03 - 2009-07-14 18:58 - 00700800 _____ () C:\Windows\system32\perfh007.dat
2015-02-06 17:03 - 2009-07-14 18:58 - 00149668 _____ () C:\Windows\system32\perfc007.dat
2015-02-06 17:03 - 2009-07-14 06:13 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-06 17:02 - 2014-03-22 15:53 - 00000000 ____D () C:\Users\julia\AppData\Roaming\Skype
2015-02-06 17:01 - 2014-04-02 21:00 - 00000256 _____ () C:\Windows\Tasks\HP Photo Creations Messager.job
2015-02-06 17:01 - 2014-03-22 18:39 - 00000000 ____D () C:\Users\julia\AppData\Local\LogMeIn Hamachi
2015-02-06 16:59 - 2014-03-20 17:07 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-02-06 16:58 - 2014-03-22 09:20 - 00075929 _____ () C:\Windows\setupact.log
2015-02-06 16:58 - 2014-03-22 09:19 - 00133092 _____ () C:\Windows\PFRO.log
2015-02-06 16:58 - 2014-03-20 16:42 - 01122246 _____ () C:\Windows\WindowsUpdate.log
2015-02-06 16:58 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-06 16:48 - 2014-03-20 17:07 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-06 16:47 - 2014-03-20 17:07 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-06 16:47 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2015-02-06 15:57 - 2014-05-04 11:06 - 00000000 ____D () C:\Users\julia\AppData\Roaming\WTablet
2015-02-04 14:48 - 2014-10-25 19:04 - 00000000 ____D () C:\Windows\Minidump
2015-02-04 14:48 - 2014-07-17 17:35 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-02-04 14:48 - 2014-04-02 20:59 - 00000000 ____D () C:\Users\julia\AppData\Roaming\HpUpdate
2015-02-04 14:48 - 2014-03-21 16:01 - 00000000 ____D () C:\Users\julia\Documents\Youcam
2015-02-04 14:48 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sysprep
2015-02-03 20:12 - 2009-07-14 04:20 - 00000000 __RHD () C:\Users\Default
2015-02-03 20:10 - 2014-03-20 17:06 - 00087336 _____ () C:\Users\julia\AppData\Local\GDIPFONTCACHEV1.DAT
2015-02-03 20:10 - 2009-07-14 05:45 - 04903592 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-03 20:10 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2015-02-03 18:43 - 2014-03-20 16:46 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-02-02 18:55 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia
2015-02-02 18:55 - 2009-07-14 03:34 - 72876032 _____ () C:\Windows\system32\config\SOFTWARE_tureg_old
2015-02-02 18:55 - 2009-07-14 03:34 - 17039360 _____ () C:\Windows\system32\config\SYSTEM_tureg_old
2015-02-02 18:55 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SECURITY_tureg_old
2015-02-02 18:51 - 2009-07-14 03:34 - 52953088 _____ () C:\Windows\system32\config\COMPONENTS_tureg_old
2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\SAM_tureg_old
2015-02-02 18:51 - 2009-07-14 03:34 - 00262144 _____ () C:\Windows\system32\config\DEFAULT_tureg_old
2015-02-02 17:50 - 2014-03-20 16:39 - 00000000 ____D () C:\Users\julia\AppData\Local\VirtualStore
2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Users\julia\AppData\Roaming\TuneUp Software
2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\ProgramData\TuneUp Software
2015-02-01 12:33 - 2014-03-20 19:09 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2013
2015-02-01 12:32 - 2014-05-30 07:57 - 00000000 ____D () C:\Users\julia\AppData\Roaming\DVDVideoSoft
2015-01-21 18:21 - 2014-08-18 20:04 - 00278270 _____ () C:\Windows\DPINST.LOG
2015-01-21 18:21 - 2014-08-18 20:03 - 00002026 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2015-01-21 18:21 - 2014-08-18 20:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2015-01-21 18:21 - 2014-03-20 22:55 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-01-14 22:56 - 2014-03-20 17:34 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 22:53 - 2014-03-20 17:34 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-07 17:10 - 2014-08-18 20:06 - 00000000 ____D () C:\Program Files (x86)\Sony Mobile
2015-01-07 12:53 - 2014-03-22 15:53 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-07 12:53 - 2014-03-22 15:53 - 00000000 ____D () C:\ProgramData\Skype
==================== Files in the root of some directories =======
2014-05-04 13:16 - 2014-08-11 16:26 - 0000132 _____ () C:\Users\julia\AppData\Roaming\Adobe PNG Format CS5 Prefs
2014-03-20 23:10 - 2014-03-21 16:42 - 0007605 _____ () C:\Users\julia\AppData\Local\Resmon.ResmonCfg
2014-04-02 20:58 - 2014-04-02 20:58 - 0000057 _____ () C:\ProgramData\Ament.ini
Some content of TEMP:
====================
C:\Users\julia\AppData\Local\Temp\avgnt.exe
C:\Users\julia\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\julia\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\julia\AppData\Local\Temp\Quarantine.exe
C:\Users\julia\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\julia\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\julia\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-05 19:01
==================== End Of Log ============================ --- --- ---
--- --- --- |