Teron821 | 22.03.2015 14:15 | AdwCleaner: Code:
# AdwCleaner v4.112 - Bericht erstellt 21/03/2015 um 17:19:12
# Aktualisiert 09/03/2015 von Xplode
# Datenbank : 2015-03-15.1 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : MeinAdmin - BAERENFROSCH
# Gestarted von : C:\Users\Leo\Desktop\AdwCleaner_4.112(1).exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Google Chrome v41.0.2272.101
*************************
AdwCleaner[R0].txt - [818 Bytes] - [21/03/2015 16:51:01]
AdwCleaner[R1].txt - [876 Bytes] - [21/03/2015 17:11:21]
AdwCleaner[S0].txt - [801 Bytes] - [21/03/2015 17:19:12]
########## EOF - \AdwCleaner\AdwCleaner[S0].txt - [859 Bytes] ########## Code:
c~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.5 (03.17.2015:1)
OS: Windows 8.1 x64
Ran by MeinAdmin on 22.03.2015 at 13:16:54,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.03.2015 at 13:23:30,00
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by MeinAdmin (administrator) on BAERENFROSCH on 22-03-2015 13:44:28
Running from C:\Users\Leo\Desktop
Loaded Profiles: Leo & MeinAdmin (Available profiles: Admin & Mama & Leo & MeinAdmin)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Realtek\REALTEK Bluetooth\BTDevMgr.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\Dragon Notes\Core\DACore.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe
(HP) C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Mozilla Corporation) C:\Users\Leo\AppData\Local\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7546072 2014-03-10] (Realtek Semiconductor)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3957816 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2818800 2014-04-22] (Synaptics Incorporated)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2014-10-31] (LogMeIn, Inc.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [126240 2014-02-13] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [475448 2014-03-04] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [313656 2013-04-18] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-02-17] (LogMeIn Inc.)
HKU\S-1-5-21-514103404-2733609734-414756415-1006\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
HKU\S-1-5-21-514103404-2733609734-414756415-1008\...\RunOnce: [Report] => \AdwCleaner\AdwCleaner[S1].txt [1061 2015-03-21] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1006\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1008\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1008\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1008\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
SearchScopes: HKLM -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-514103404-2733609734-414756415-1006 -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-514103404-2733609734-414756415-1008 -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2015-01-10] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-01-10] (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-03-04] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-22] ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-01-10] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-01-10] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-22] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
StartMenuInternet: FIREFOX.EXE - C:\Users\Leo\AppData\Local\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-21] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2015-01-23] ()
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [88064 2014-03-05] () [File not signed]
R2 DACoreService; C:\Program Files (x86)\Nuance\Dragon Notes\Core\DACore.exe [411024 2013-02-01] (Nuance Communications, Inc.)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-28] (WildTangent)
R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2011-10-17] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [174592 2012-12-04] (HP) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [469304 2014-03-04] (Hewlett-Packard Development Company, L.P.)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-02-16] (LogMeIn, Inc.)
S4 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [226152 2014-10-31] (LogMeIn, Inc.)
S4 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2014-10-31] (LogMeIn, Inc.)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-01] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [191728 2014-04-22] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-11-04] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-12-20] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-02-17] (LogMeIn Inc.)
R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2014-10-31] (LogMeIn, Inc.)
S4 LMIRfsClientNP; No ImagePath
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-01-06] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3379416 2014-03-22] (Realtek Semiconductor Corporation )
R3 SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver_AMDASF.sys [30448 2014-04-22] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [31472 2014-04-22] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
S3 GENERICDRV; \??\C:\Users\ADMINI~1\AppData\Local\Temp\pftDAE8.tmp\amifldrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-22 13:40 - 2015-03-22 13:40 - 00000619 _____ () C:\Users\MeinAdmin\Desktop\JRT2.txt
2015-03-22 13:23 - 2015-03-22 13:23 - 00000618 _____ () C:\Users\MeinAdmin\Desktop\JRT.txt
2015-03-21 18:28 - 2015-03-21 18:28 - 00000619 _____ () C:\Users\MeinAdmin\Documents\JRT.txt
2015-03-21 18:07 - 2015-03-21 18:07 - 01388672 _____ (Thisisu) C:\Users\Leo\Desktop\JRT.exe
2015-03-21 16:50 - 2015-03-21 17:42 - 00000000 ____D () C:\AdwCleaner
2015-03-21 16:49 - 2015-03-21 16:49 - 02171392 _____ () C:\Users\Leo\Desktop\AdwCleaner_4.112(1).exe
2015-03-21 15:17 - 2015-03-21 15:17 - 00000000 ____D () C:\Users\Public\Pokki
2015-03-21 14:47 - 2015-03-21 14:47 - 00001287 _____ () C:\Users\MeinAdmin\Desktop\Revo Uninstaller.lnk
2015-03-21 14:47 - 2015-03-21 14:47 - 00000000 __SHD () C:\Users\MeinAdmin\AppData\Local\EmieBrowserModeList
2015-03-21 14:47 - 2015-03-21 14:47 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-21 14:46 - 2015-03-21 14:47 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Leo\Downloads\revosetup95.exe
2015-03-21 14:39 - 2015-03-21 14:40 - 00029214 _____ () C:\Users\Leo\Desktop\Addition.txt
2015-03-21 14:12 - 2015-03-21 14:13 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Leo\Downloads\mbam-setup-2.1.4.1018.exe
2015-03-21 14:11 - 2015-03-21 14:11 - 02171392 _____ () C:\Users\Leo\Downloads\adwcleaner_4.112.exe
2015-03-21 13:59 - 2015-03-21 14:00 - 00000000 ____D () C:\Users\Leo\AppData\Local\Mozilla Firefox
2015-03-21 13:44 - 2015-03-22 13:44 - 00017619 _____ () C:\Users\Leo\Desktop\FRST.txt
2015-03-21 13:44 - 2015-03-22 13:44 - 00000000 ____D () C:\FRST
2015-03-21 13:42 - 2015-03-21 13:42 - 02095616 _____ (Farbar) C:\Users\Leo\Desktop\FRST64.exe
2015-03-21 13:37 - 2015-03-21 13:37 - 00001418 _____ () C:\Users\Leo\Desktop\Events.txt
2015-03-12 02:00 - 2015-03-12 02:00 - 00002813 _____ () C:\Users\Leo\AppData\Local\recently-used.xbel
2015-03-06 13:33 - 2015-03-06 13:34 - 02574000 _____ () C:\Users\Leo\Downloads\castle1.bsp
2015-03-06 10:37 - 2015-03-06 10:37 - 06758533 _____ () C:\Users\Leo\Downloads\KAS_0.4.10.zip
2015-03-06 10:34 - 2015-03-06 10:34 - 00043889 _____ () C:\Users\Leo\Downloads\targetron_1_3_4.zip
2015-03-06 10:30 - 2015-03-06 10:32 - 40723506 _____ () C:\Users\Leo\Downloads\Firespitter_634.zip
2015-03-06 10:27 - 2015-03-06 10:27 - 02368280 _____ () C:\Users\Leo\Downloads\Romfarer_LazorSystem_v35.zip
2015-03-06 10:24 - 2015-03-06 10:25 - 04325650 _____ () C:\Users\Leo\Downloads\MechJeb2-2.4.2.0.zip
2015-03-06 01:32 - 2015-03-06 01:38 - 00000000 ____D () C:\Users\Leo\workspace
2015-03-06 01:32 - 2015-03-06 01:32 - 00000000 ____D () C:\Users\Leo\AppData\Local\Eclipse
2015-03-06 01:29 - 2015-03-06 01:31 - 00000000 ____D () C:\Users\Leo\eclipse
2015-03-05 23:59 - 2015-03-05 23:59 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2015-03-05 23:32 - 2015-03-05 23:40 - 162162770 _____ () C:\Users\Leo\eclipse-java-luna-SR2-win32-x86_64.zip
2015-03-01 20:26 - 2015-03-01 20:26 - 00000000 ____D () C:\Users\MeinAdmin\Documents\Youcam
2015-03-01 20:26 - 2015-03-01 20:26 - 00000000 ____D () C:\Users\MeinAdmin\AppData\Local\Logitech
2015-03-01 20:26 - 2015-03-01 20:26 - 00000000 ____D () C:\Users\MeinAdmin\AppData\Local\CyberLink
2015-03-01 20:22 - 2015-03-10 14:18 - 00043576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-03-01 20:21 - 2015-03-01 20:21 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\Avira
2015-03-01 20:05 - 2015-03-10 14:18 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-03-01 20:05 - 2015-03-10 14:18 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-03-01 20:05 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-03-01 19:58 - 2015-03-01 19:58 - 00001226 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-03-01 19:57 - 2015-03-01 20:05 - 00000000 ____D () C:\ProgramData\Avira
2015-03-01 19:57 - 2015-03-01 20:05 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-03-01 17:30 - 2015-03-01 17:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\GeoGebra 5.0
2015-02-28 10:51 - 2015-02-28 10:51 - 00001712 _____ () C:\Users\Leo\Desktop\GeoGebra.lnk
2015-02-28 10:51 - 2015-02-28 10:51 - 00000000 ____D () C:\Users\Leo\GeoGebra 5.0
2015-02-28 10:51 - 2015-02-28 10:51 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GeoGebra 5
2015-02-22 11:09 - 2015-02-22 11:09 - 00000222 _____ () C:\Users\Leo\Desktop\HIT.url
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-22 13:45 - 2014-11-07 23:31 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-22 13:42 - 2014-10-05 22:13 - 00000000 ____D () C:\Spiele
2015-03-22 13:41 - 2014-10-20 13:09 - 00000000 ____D () C:\Users\MeinAdmin\Documents\My Cheat Tables
2015-03-22 13:40 - 2014-10-01 19:23 - 00000000 ____D () C:\Users\Leo\Documents\Youcam
2015-03-22 13:36 - 2014-10-01 18:18 - 01725396 _____ () C:\Windows\WindowsUpdate.log
2015-03-22 13:15 - 2014-11-07 23:31 - 00001140 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-22 13:15 - 2014-10-01 19:21 - 00000000 ____D () C:\Users\Leo\AppData\Local\Pokki
2015-03-22 13:15 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-03-21 18:29 - 2014-10-01 19:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\ClassicShell
2015-03-21 17:51 - 2014-04-30 23:19 - 00800954 _____ () C:\Windows\system32\perfh007.dat
2015-03-21 17:51 - 2014-04-30 23:19 - 00174458 _____ () C:\Windows\system32\perfc007.dat
2015-03-21 17:51 - 2014-03-18 10:53 - 01921154 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-21 17:43 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-21 17:43 - 2013-08-22 14:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2015-03-21 17:42 - 2014-06-10 20:25 - 00065536 _____ () C:\Windows\system32\spu_storage.bin
2015-03-21 17:20 - 2014-03-18 10:44 - 00153310 _____ () C:\Windows\PFRO.log
2015-03-21 16:27 - 2014-10-01 19:27 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-514103404-2733609734-414756415-1006
2015-03-21 15:46 - 2014-11-01 15:04 - 00057344 ___SH () C:\Users\Leo\Desktop\Thumbs.db
2015-03-21 15:25 - 2013-08-22 16:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-21 13:51 - 2014-11-07 23:33 - 00002202 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-13 21:12 - 2014-10-01 19:31 - 00000000 ____D () C:\Users\MeinAdmin
2015-03-13 19:29 - 2015-01-18 14:28 - 00002338 _____ () C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-03-12 21:03 - 2014-10-01 19:21 - 00000000 ____D () C:\Users\Leo
2015-03-12 21:03 - 2014-10-01 19:14 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-03-12 01:58 - 2015-01-10 14:40 - 00000000 ____D () C:\Users\Leo\AppData\Local\gtk-2.0
2015-03-12 01:54 - 2015-01-10 14:33 - 00000000 ____D () C:\Users\Leo\.gimp-2.8
2015-03-12 01:51 - 2014-10-02 07:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\vlc
2015-03-11 00:51 - 2014-12-28 02:16 - 00000045 _____ () C:\Users\Leo\Documents\Isaac.txt
2015-03-08 20:58 - 2013-08-22 15:46 - 00032607 _____ () C:\Windows\setupact.log
2015-03-06 15:06 - 2014-10-02 14:43 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\TS3Client
2015-03-03 18:51 - 2014-06-10 20:41 - 00000000 ____D () C:\ProgramData\McAfee
2015-03-03 18:51 - 2014-06-10 20:41 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-03-01 20:26 - 2014-11-07 23:38 - 00000000 ____D () C:\Users\MeinAdmin\AppData\Roaming\ClassicShell
2015-03-01 19:57 - 2014-06-10 20:11 - 00000000 ____D () C:\ProgramData\Package Cache
2015-03-01 19:56 - 2013-08-22 16:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2015-03-01 19:54 - 2015-02-07 13:58 - 00000000 ____D () C:\Users\Mama
2015-03-01 19:43 - 2014-11-07 23:33 - 00000000 ____D () C:\Users\Leo\AppData\Local\LogMeIn Hamachi
2015-02-25 21:48 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2015-02-22 17:11 - 2014-10-02 10:23 - 00000000 ____D () C:\Users\MeinAdmin\AppData\Local\Adobe
2015-02-22 15:35 - 2014-11-05 21:54 - 00261632 ___SH () C:\Users\Leo\Downloads\Thumbs.db
==================== Files in the root of some directories =======
2014-12-18 14:05 - 2014-12-18 14:05 - 0007626 _____ () C:\Users\MeinAdmin\AppData\Local\Resmon.ResmonCfg
Some content of TEMP:
====================
C:\Users\Leo\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll
C:\Users\Leo\AppData\Local\Temp\7941aa9f1a1ffb54e75f6abe950bcdb6.dll
C:\Users\Leo\AppData\Local\Temp\avgnt.exe
C:\Users\Leo\AppData\Local\Temp\COMAP.EXE
C:\Users\Leo\AppData\Local\Temp\ipyzdlw8.dll
C:\Users\Leo\AppData\Local\Temp\oct6287.tmp.exe
C:\Users\Leo\AppData\Local\Temp\octD4B.tmp.exe
C:\Users\Leo\AppData\Local\Temp\octD699.tmp.exe
C:\Users\Leo\AppData\Local\Temp\octE7D5.tmp.exe
C:\Users\MeinAdmin\AppData\Local\Temp\avgnt.exe
C:\Users\MeinAdmin\AppData\Local\Temp\Quarantine.exe
C:\Users\MeinAdmin\AppData\Local\Temp\sqlite3.dll
C:\Users\MeinAdmin\AppData\Local\Temp\_isD2.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-21 16:27
==================== End Of Log ============================ --- --- ---
--- --- --- |