Alltagheldin | 08.02.2015 12:49 | Danke, habe alles ausgeführt, wenn ich Google starte sieht die Startseite immer noch "seltsam" aus, die Ads sind noch vorhanden, vorallem wenn ich auf Eurer Seite bin, ein Anklicken der Links kaum möglich. Ich konnte mir von euerer Ponyfile Seite die Programme auch nicht ziehen, habe entweder Warnmeldung von Mbam bekommen oder bin umgeleitet worden - habe sie mir dann auf Chip gezogen - hatte mir vorher deine Anweisungen ausgedruckt, da ich kaum noch Platz auf dem Bildschirm für Eure Anweisungen habe, habe das Gefühl die Ads "wachsen". Habe einen screenshot von eurer Seite gemacht - ich hänte ihn hier mal dran - das ist schon schwierig, da die uploadfunktion fast von den neuen Ads überdeckt wird. Hier kommen nun die text files.(In Reihenfolge: Mbam, adwcleaner, jrt, frst.
Danke erstmal, ich habe trotzdem Hoffnung, dass ich heute noch etwas arbeiten kann. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 08.02.2015
Suchlauf-Zeit: 11:32:03
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.02.08.04
Rootkit Datenbank: v2015.02.03.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: L
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 374646
Verstrichene Zeit: 17 Min, 26 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 12
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{30c85a3d-1d96-4589-b63f-91fb7ef45a41}, In Quarantäne, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{63c63464-1423-4fdb-ba5d-6f75f491c63e}, In Quarantäne, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{50F60937-910A-4C05-8E36-FE4E299191CF}, In Quarantäne, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{50F60937-910A-4C05-8E36-FE4E299191CF}, In Quarantäne, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{63c63464-1423-4fdb-ba5d-6f75f491c63e}, In Quarantäne, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.FindPositive.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}, In Quarantäne, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.FindPositive.A, HKU\S-1-5-21-1857655392-2268603011-1377333626-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}, Löschen bei Neustart, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.FindPositive.A, HKU\S-1-5-21-1857655392-2268603011-1377333626-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{30C85A3D-1D96-4589-B63F-91FB7EF45A41}, Löschen bei Neustart, [b3519c806822dc5ab08298646e946b95],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1857655392-2268603011-1377333626-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Löschen bei Neustart, [34d0839964265ed888dd28d9e0230ff1],
PUP.Optional.IEPluginServices.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\IePluginService, In Quarantäne, [2cd8f923622872c4e3372e65cc374cb4],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1857655392-2268603011-1377333626-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Löschen bei Neustart, [e71d66b699f19d998f7cefe1020112ee],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1857655392-2268603011-1377333626-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Löschen bei Neustart, [8e7660bcbbcf8aacbc6219cddb29b34d],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1857655392-2268603011-1377333626-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0V1D1S1R1D0V1O, Löschen bei Neustart, [8e7660bcbbcf8aacbc6219cddb29b34d]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 9
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\1F772598BAED4DDE91189C06B89600A5, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\5D84139A03C445F4945A82C6DB6100D3, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\C5C5C0E200C44CD491EC14E90116D922, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\E5EC5634B876447587DBB8E03FD8148F, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService, In Quarantäne, [3dc721fbf09a5dd962f4351cd330a060],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update, In Quarantäne, [3dc721fbf09a5dd962f4351cd330a060],
PUP.Optional.Extutil.A, C:\Users\L\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, In Quarantäne, [7490fc206a20ea4c0fcf2045e41fb14f],
PUP.Optional.Managera.A, C:\Users\L\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, In Quarantäne, [e0242fedf5953cfa0ad576eff112e719],
Dateien: 35
PUP.Optional.Conduit.A, C:\Users\L\AppData\Roaming\OpenCandy\5D84139A03C445F4945A82C6DB6100D3\SSStub_SearchProtect_p1v0.exe, In Quarantäne, [30d4bf5d4446b28456a8024030d156aa],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nsk28AC.exe, In Quarantäne, [8f75da42aedcd462963872ddfd04ce32],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nslD601.exe, In Quarantäne, [4db7ad6fdbaf290dd4fad27d5da454ac],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nsm92A0.exe, In Quarantäne, [45bfbe5e15759c9ab71774db1be6cd33],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nsnB094.exe, In Quarantäne, [9371071594f6142258765bf40af760a0],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nso330.exe, In Quarantäne, [3cc81b01503a72c4735ba6a9ba47f10f],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nscAD96.exe, In Quarantäne, [689c62ba6f1b13234886b79826dbf20e],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nscFF86.exe, In Quarantäne, [c143db41dfabb086814da2ad02ff857b],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nsd8A89.exe, In Quarantäne, [b94bd94399f18da9ab2326295fa2d729],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nse8D97.exe, In Quarantäne, [a064ff1dd1b9ea4c12bc94bbd82929d7],
PUP.Optional.SearchProtect.A, C:\Users\L\AppData\Local\Temp\nshD8F0.exe, In Quarantäne, [a55f60bcf6941323696554fb06fb0df3],
PUP.Optional.Conduit.A, C:\Users\L\AppData\Local\Temp\nsfBAA8\SpSetup.exe, In Quarantäne, [f014be5e2268c96d9929a4a09c65817f],
PUP.Optional.Conduit.A, C:\Users\L\AppData\Local\Temp\nsh6E84\SpSetup.exe, In Quarantäne, [937155c7dfab102690326fd532cf4cb4],
PUP.Optional.SkyTech.A, C:\Users\L\AppData\Local\Temp\fullpackage_temp1398502324\alilog.dll, In Quarantäne, [1de71b0185054ee865bf24d81ee350b0],
PUP.Optional.Skytech.A, C:\Users\L\AppData\Local\Temp\fullpackage_temp1398502324\package1.zip, In Quarantäne, [7b893ede26640d29f39e9418b44dc63a],
PUP.Optional.V9.A, C:\Users\L\AppData\Local\Temp\fullpackage_temp1398502324\qSE.exe, In Quarantäne, [36ceeb314c3e38fee2497ccd03fd2cd4],
PUP.Optional.Skytech.A, C:\Users\L\AppData\Local\Temp\fullpackage_temp1398502324\UninstallManager.exe, In Quarantäne, [956fd24aaddd989e375a892357aa3bc5],
PUP.Optional.IePluginService.A, C:\Users\L\AppData\Local\Temp\fullpackage_temp1398502324\tmp\SupTab.exe, In Quarantäne, [030114080f7b0234bce9fc8037caf20e],
PUP.Optional.WpManager, C:\Users\L\AppData\Local\Temp\fullpackage_temp1398502324\tmp\wpm.exe, In Quarantäne, [64a007155436b97ddb812265758cca36],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Local\Temp\is-559FH.tmp\OCSetupHlp.dll, In Quarantäne, [08fc54c84b3f1d1947d728b5e223e917],
PUP.Adware.Agent, C:\Users\L\AppData\Local\Temp\PositiveFinds\Setup.exe, In Quarantäne, [29dbad6f9ded3ff7a32729dd37c9659b],
PUP.Optional.AZLyrics.A, C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage, In Quarantäne, [5fa5e23a068411253b7298f8bf4432ce],
PUP.Optional.AZLyrics.A, C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal, In Quarantäne, [b54f60bc4c3e1521129ba5eb3ec5916f],
PUP.Optional.MindSpark.A, C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_eliteunzip.dl.tb.ask.com_0.localstorage, In Quarantäne, [00042bf1127872c40ed02b93ae55f907],
PUP.Optional.MindSpark.A, C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_eliteunzip.dl.tb.ask.com_0.localstorage-journal, In Quarantäne, [f0147e9ec8c2979f538b7d4123e0867a],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\1F772598BAED4DDE91189C06B89600A5\Trial-14.0.1000.89_de-DE_1004733_DE-2.exe, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\C5C5C0E200C44CD491EC14E90116D922\du.exe, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\C5C5C0E200C44CD491EC14E90116D922\setup0116.exe, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.OpenCandy, C:\Users\L\AppData\Roaming\OpenCandy\E5EC5634B876447587DBB8E03FD8148F\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [63a1120a8802d2642497113d32d124dc],
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginService\update\conf, In Quarantäne, [3dc721fbf09a5dd962f4351cd330a060],
PUP.Optional.Extutil.A, C:\Users\L\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, In Quarantäne, [7490fc206a20ea4c0fcf2045e41fb14f],
PUP.Optional.Extutil.A, C:\Users\L\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js, In Quarantäne, [7490fc206a20ea4c0fcf2045e41fb14f],
PUP.Optional.Extutil.A, C:\Users\L\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, In Quarantäne, [7490fc206a20ea4c0fcf2045e41fb14f],
PUP.Optional.Managera.A, C:\Users\L\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, In Quarantäne, [e0242fedf5953cfa0ad576eff112e719],
PUP.Optional.Managera.A, C:\Users\L\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, In Quarantäne, [e0242fedf5953cfa0ad576eff112e719],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
# AdwCleaner v4.110 - Bericht erstellt 08/02/2015 um 12:11:14
# Aktualisiert 05/02/2015 von Xplode
# Datenbank : 2015-02-05.2 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : L - UTESPC
# Gestarted von : C:\Users\L\Desktop\adwcleaner_4.110.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Users\L\AppData\Local\Temp\WiseEnhance
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_services.hearstmags.com_0.localstorage-journal
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_services.hearstmags.com_0.localstorage
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
Datei Gelöscht : C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\Wpm
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\SOFTWARE\PositiveFinds
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Google Chrome v40.0.2214.111
*************************
AdwCleaner[R0].txt - [2969 Bytes] - [08/02/2015 12:08:58]
AdwCleaner[S0].txt - [2837 Bytes] - [08/02/2015 12:11:14]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2896 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.2 (02.02.2015:1)
OS: Windows 8.1 x64
Ran by L on 08.02.2015 at 12:21:55,78
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\Users\L\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage"
Successfully deleted: [File] "C:\Users\L\appdata\local\google\chrome\user data\default\local storage\http_www.superfish.com_0.localstorage-journal"
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.02.2015 at 12:24:59,20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-02-2015
Ran by L (administrator) on UTESPC on 08-02-2015 12:32:49
Running from C:\Users\L\Downloads
Loaded Profiles: UpdatusUser & L (Available profiles: UpdatusUser & L)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> csrss.exe
Failed to access process -> services.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) D:\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) D:\Avira\AntiVir Desktop\avguard.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) D:\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
() C:\Users\L\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\hidfind.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
(Avira Operations GmbH & Co. KG) D:\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\msosync.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\L\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13651672 2013-09-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-31] (Realtek Semiconductor)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [688984 2013-08-07] (Alps Electric Co., Ltd.)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6340312 2013-08-03] (Realtek semiconductor)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2013-12-17] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2013-12-17] (Lenovo(beijing) Limited)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [Lenovo App Shop] => C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\ismagent.exe [156000 2013-07-18] (Intel Corporation)
HKLM-x32\...\Run: [avgnt] => D:\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-11] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126712 2014-12-31] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications))
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\...\Run: [Polar FlowSync] => [X]
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\...\Run: [Amazon Cloud Player] => C:\Users\L\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe [3145536 2014-05-08] ()
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\...\Run: [Facebook Update] => C:\Users\L\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2014-06-15] (Facebook Inc.)
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\...\Run: [GoogleChromeAutoLaunch_20C3476E9F850696941C9C56497DE747] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [843592 2015-02-04] (Google Inc.)
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [22041192 2014-08-27] (Skype Technologies S.A.)
Startup: C:\Users\L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1857655392-2268603011-1377333626-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1857655392-2268603011-1377333626-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1857655392-2268603011-1377333626-1002 -> {1326E841-9028-4B4A-A6E6-702ACDDA673C} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKU\S-1-5-21-1857655392-2268603011-1377333626-1002: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\L\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF Plugin HKU\S-1-5-21-1857655392-2268603011-1377333626-1002: intel.com/AppUp -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp.dll (Intel)
FF Plugin HKU\S-1-5-21-1857655392-2268603011-1377333626-1002: intel.com/AppUpx64 -> C:\Program Files (x86)\Lenovo\LenovoAppShop\bin\npAppUp_x64.dll (Intel)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.trovigo.com/?gd=&ctid=CT3315513&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=4&UP=SP6C3F6A9D-78DA-4333-9FFB-97ABAE244984&SSPV=
CHR StartupUrls: Default -> "hxxp://search.conduit.com/?ctid=CT3318001&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP6C3F6A9D-78DA-4333-9FFB-97ABAE244984&SSPV=", "hxxp://search.conduit.com/?ctid=CT3318001&octid=EB_ORIGINAL_CTID&SearchSource=55&CUI=&UM=2&UP=SP7C2EBD25-2D08-4548-BEEC-249E2D12482E&SSPV=", "hxxp://www.sweet-page.com/?type=hp&ts=1398502332&from=cor&uid=ST500LM000-SSHD-8GB_W371H6JCXXXXW371H6JC", "hxxp://www.sweet-page.com/?type=hppp&ts=1398507421&from=cor&uid=ST500LM000-SSHD-8GB_W371H6JCXXXXW371H6JC", "hxxp://www.sweet-page.com/?type=hppp&ts=1398507813&from=cor&uid=ST500LM000-SSHD-8GB_W371H6JCXXXXW371H6JC"
CHR Profile: C:\Users\L\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-02-26]
CHR Extension: (Google Drive) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-02-26]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-04]
CHR Extension: (YouTube) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-02-26]
CHR Extension: (Google-Suche) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-02-26]
CHR Extension: (Avira Browserschutz) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-11]
CHR Extension: (Skype Click to Call) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-21]
CHR Extension: (Google Wallet) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-02-26]
CHR Extension: (Google Mail) - C:\Users\L\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-02-26]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - No Path
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; D:\Avira\AntiVir Desktop\sched.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; D:\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-11] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [178424 2014-12-31] (Avira Operations GmbH & Co. KG)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-12] (Microsoft Corporation)
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [243880 2015-01-16] (Foxit Software Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-22] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-04] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [163624 2013-10-17] (PointGrab LTD)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-25] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2013-12-17] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-07] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3859968 2013-08-15] (Qualcomm Atheros Communications, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
S3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [100072 2013-08-03] (GenesysLogic)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-08] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8873688 2013-08-03] (Realtek Semiconductor Corp.)
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-08 12:24 - 2015-02-08 12:24 - 00000902 _____ () C:\Users\L\Desktop\JRT.txt
2015-02-08 12:19 - 2015-02-08 12:19 - 01388274 _____ (Thisisu) C:\Users\L\Desktop\JRT42.exe
2015-02-08 12:14 - 2015-02-08 12:14 - 00002984 _____ () C:\Users\L\Desktop\AdwCleaner[S0].txt
2015-02-08 12:08 - 2015-02-08 12:11 - 00000000 ____D () C:\AdwCleaner
2015-02-08 12:06 - 2015-02-08 12:06 - 02112512 _____ () C:\Users\L\Desktop\adwcleaner_4.110.exe
2015-02-08 11:58 - 2015-02-08 11:58 - 00010121 _____ () C:\Users\L\Desktop\mbam.txt
2015-02-08 11:30 - 2015-02-08 12:13 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-02-08 11:30 - 2015-02-08 11:30 - 00001129 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-08 11:30 - 2015-02-08 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-08 11:30 - 2015-02-08 11:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-08 11:30 - 2015-02-08 11:30 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-08 11:30 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-02-08 11:30 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-02-08 11:30 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-02-08 11:29 - 2015-02-08 11:29 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\L\Downloads\mbam-setup-2.0.4.1028.exe
2015-02-08 11:17 - 2015-02-08 11:17 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\L\Downloads\revosetup95.exe
2015-02-08 11:17 - 2015-02-08 11:17 - 00001295 _____ () C:\Users\L\Desktop\Revo Uninstaller.lnk
2015-02-08 11:17 - 2015-02-08 11:17 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-02-07 17:20 - 2015-02-07 17:21 - 00036165 _____ () C:\Users\L\Downloads\Addition.txt
2015-02-07 17:19 - 2015-02-08 12:33 - 00022183 _____ () C:\Users\L\Downloads\FRST.txt
2015-02-07 17:19 - 2015-02-08 12:32 - 00000000 ____D () C:\FRST
2015-02-07 17:18 - 2015-02-07 17:18 - 02132992 _____ (Farbar) C:\Users\L\Downloads\FRST64.exe
2015-02-07 17:18 - 2015-02-07 17:18 - 02132992 _____ (Farbar) C:\Users\L\Downloads\FRST64 (1).exe
2015-02-06 10:48 - 2015-02-06 10:48 - 00000000 ____D () C:\Users\L\Documents\Any Video Converter
2015-02-06 10:42 - 2015-02-06 10:42 - 00001230 _____ () C:\Users\L\Desktop\Any Video Converter.lnk
2015-02-06 10:42 - 2015-02-06 10:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anvsoft
2015-02-06 10:41 - 2015-02-06 10:48 - 00000000 ____D () C:\Users\L\AppData\Roaming\Anvsoft
2015-02-06 10:41 - 2015-02-06 10:41 - 00000000 ____D () C:\Program Files (x86)\Anvsoft
2015-02-06 10:40 - 2015-02-06 10:40 - 33703656 _____ (Any-Video-Converter.com ) C:\Users\L\Downloads\avc-577free.exe
2015-02-05 11:21 - 2015-02-05 11:21 - 31470563 _____ () C:\Users\L\Downloads\MediathekView_8.zip
2015-02-05 11:21 - 2015-02-05 11:21 - 00000000 ____D () C:\Users\L\Downloads\MediathekView_8
2015-02-02 21:21 - 2015-02-02 21:21 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-01-25 20:02 - 2015-01-25 20:02 - 00309585 _____ () C:\Users\L\Downloads\BLS_3.0X_Lizenzmodelle_und_Nutzungsbedingungen_03.zip
2015-01-25 19:40 - 2015-02-06 10:39 - 00000000 ____D () C:\WINDOWS\Lhsp
2015-01-25 19:33 - 2015-01-25 19:34 - 68628254 _____ (directINNOVATION UG (haftungsbeschränkt) ) C:\Users\L\Downloads\mwsr5_setup (2).exe
2015-01-20 22:26 - 2015-01-20 22:26 - 00000000 ____D () C:\Users\L\Documents\alt
2015-01-14 18:05 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-14 18:05 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-14 18:05 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-14 18:05 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-14 18:05 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-14 18:05 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-14 18:05 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-14 18:05 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-14 18:05 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-14 18:05 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-14 18:05 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-14 18:05 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-14 18:05 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-14 18:05 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-14 18:05 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-14 18:05 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-14 18:05 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-14 18:05 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-14 18:05 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-14 18:05 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-14 18:05 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-14 18:05 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-14 18:05 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-14 18:05 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-14 18:05 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-14 18:05 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-14 18:05 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-14 18:05 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-14 18:05 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-14 18:05 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-14 18:05 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2015-01-13 21:31 - 2015-01-13 21:31 - 00000000 ____D () C:\Users\L\Downloads\kaloma
2015-01-13 21:30 - 2015-01-13 21:30 - 01742101 _____ () C:\Users\L\Downloads\kaloma.zip
2015-01-13 20:42 - 2015-01-13 20:45 - 00000012 _____ () C:\Users\L\Documents\test.li
2015-01-13 20:41 - 2015-01-13 20:45 - 00000000 ____D () C:\Users\L\Documents\ebisdemo
2015-01-13 20:41 - 2015-01-13 20:41 - 00000929 _____ () C:\Users\L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EBISpro Demo.lnk
2015-01-13 20:40 - 2015-01-13 20:40 - 01654260 _____ () C:\Users\L\Downloads\ebisdemo.exe
2015-01-11 12:01 - 2015-01-11 12:01 - 02852162 _____ () C:\Users\L\Downloads\Angewandte_Ernaehrungslehre_und_Bromatologie_Teil_2 (1).zip
2015-01-10 19:03 - 2015-01-10 19:03 - 01960410 _____ () C:\Users\L\Downloads\Diaettherapie (1).zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-08 12:27 - 2014-02-26 16:46 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1857655392-2268603011-1377333626-1002
2015-02-08 12:15 - 2014-03-23 20:14 - 00196096 ___SH () C:\Users\L\Desktop\Thumbs.db
2015-02-08 12:15 - 2014-02-26 17:44 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-02-08 12:14 - 2014-12-27 19:30 - 00005112 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for UTESPC-L UtesPc
2015-02-08 12:14 - 2014-02-26 19:08 - 00000000 ____D () C:\Users\L\Documents\Outlook-Dateien
2015-02-08 12:13 - 2014-04-02 17:49 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cf4e937ce60b81.job
2015-02-08 12:13 - 2014-02-26 16:47 - 00000000 __RDO () C:\Users\L\SkyDrive
2015-02-08 12:12 - 2013-10-07 19:23 - 00141144 _____ () C:\WINDOWS\PFRO.log
2015-02-08 12:12 - 2013-08-22 15:46 - 00277728 _____ () C:\WINDOWS\setupact.log
2015-02-08 12:12 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-02-08 12:11 - 2013-12-17 01:56 - 00006656 _____ () C:\WINDOWS\system32\VfService.trf
2015-02-08 12:11 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-02-08 12:10 - 2013-12-17 01:29 - 01636620 _____ () C:\WINDOWS\WindowsUpdate.log
2015-02-08 12:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-02-08 11:59 - 2014-09-20 19:54 - 00000000 ____D () C:\Users\L\AppData\Roaming\Skype
2015-02-08 11:53 - 2014-03-03 06:28 - 00000000 ___RD () C:\WINDOWS\BrowserChoice
2015-02-08 11:53 - 2013-08-22 15:44 - 00490248 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-02-08 11:43 - 2014-04-12 17:42 - 00000689 _____ () C:\WINDOWS\BRRBCOM.INI
2015-02-08 11:06 - 2014-06-15 13:01 - 00000926 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1857655392-2268603011-1377333626-1002UA.job
2015-02-08 10:29 - 2014-02-26 17:42 - 00003906 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5A5A6C08-3E6C-4FED-92B4-3069DA6FA95B}
2015-02-07 20:54 - 2014-07-16 18:04 - 00000000 ____D () C:\Users\L\Documents\nähen
2015-02-07 19:01 - 2014-03-04 13:09 - 01089024 ___SH () C:\Users\L\Downloads\Thumbs.db
2015-02-07 17:49 - 2014-07-24 10:20 - 00000000 ____D () C:\Users\L\Downloads\Studienanleitung_Persoenlichkeitspsychologie_Teil_2 (2)
2015-02-07 14:06 - 2014-06-15 13:01 - 00000904 _____ () C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1857655392-2268603011-1377333626-1002Core.job
2015-02-07 11:16 - 2014-02-26 17:45 - 00002206 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-02-06 12:56 - 2013-08-22 16:20 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-02-06 12:45 - 2014-03-02 21:36 - 00000000 ____D () C:\Users\L\AppData\Roaming\vlc
2015-02-06 12:17 - 2014-05-19 18:05 - 00000000 ____D () C:\Users\L\MediathekView
2015-02-05 11:22 - 2014-05-19 18:03 - 00000000 ____D () C:\Users\L\.mediathek3
2015-02-05 10:10 - 2014-04-02 17:49 - 00003868 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1cf4e937ce60b81
2015-02-05 10:10 - 2014-02-26 17:44 - 00004104 _____ () C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-02-03 20:31 - 2014-05-18 08:16 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-02-03 20:31 - 2014-05-18 08:16 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-02-03 20:18 - 2013-12-17 10:11 - 00766620 _____ () C:\WINDOWS\system32\perfh007.dat
2015-02-03 20:18 - 2013-12-17 10:11 - 00159902 _____ () C:\WINDOWS\system32\perfc007.dat
2015-02-03 20:18 - 2013-10-07 19:27 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-02-02 22:19 - 2014-03-04 12:55 - 00000000 ____D () C:\Users\L\Documents\aaa studium
2015-02-02 22:19 - 2014-02-26 16:41 - 00000000 ____D () C:\Users\L\AppData\Local\Packages
2015-02-02 21:21 - 2014-08-07 09:40 - 00001164 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-02-02 21:21 - 2014-08-07 09:40 - 00000000 ____D () C:\ProgramData\Package Cache
2015-02-02 21:21 - 2014-04-07 19:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-02-01 12:47 - 2014-04-19 17:06 - 00000000 ____D () C:\Users\L\Documents\beruf
2015-01-28 19:15 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\NDF
2015-01-25 19:40 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\Speech
2015-01-25 17:37 - 2014-03-06 21:04 - 00000000 ____D () C:\Users\L\Documents\gesundheit
2015-01-25 12:22 - 2014-05-29 16:15 - 00000000 ____D () C:\ProgramData\boost_interprocess
2015-01-20 22:26 - 2014-06-08 10:04 - 00000000 ____D () C:\Users\L\Documents\dino
2015-01-14 18:37 - 2014-03-02 16:21 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-01-14 18:30 - 2014-03-02 16:21 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-01-13 20:41 - 2014-02-26 16:41 - 00000000 ____D () C:\Users\L\AppData\Local\VirtualStore
2015-01-09 21:30 - 2014-09-22 16:55 - 00000000 ____D () C:\Users\L\Documents\telekom
==================== Files in the root of some directories =======
2013-12-17 01:37 - 2013-12-17 01:37 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some content of TEMP:
====================
C:\Users\L\AppData\Local\Temp\avgnt.exe
C:\Users\L\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\L\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\L\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\L\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\L\AppData\Local\Temp\OfficeSetup.exe
C:\Users\L\AppData\Local\Temp\Quarantine.exe
C:\Users\L\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\L\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\L\AppData\Local\Temp\sqlite3.dll
C:\Users\L\AppData\Local\Temp\tester.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-26 19:36
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- --- |