Teron821 | 21.03.2015 13:51 | Tschuldige war die letzte woche nicht da.
Aber Hier di LOG´s von Avira Free antivirus.
sind vom 14.3 leider ist bei diesem scan Avira nicht fertig geworden. Code:
Exported events:
14.03.2015 02:48 [System Scanner] Malware found
The file
'C:\$Recycle.Bin\S-1-5-21-514103404-2733609734-414756415-1006\$R45WHRQ.exe'
contained a virus or unwanted program 'PUA/Somoto.Gen' [riskware]
Action(s) taken:
The file was moved to the quarantine directory under the name '48ba1d97.qua'!
14.03.2015 02:48 [System Scanner] Malware found
The file
'C:\Users\Leo\AppData\Roaming\.minecraft\mods\JourneyMap5.0.0RC1_Unlimited_MC1.7
.10.jar'
contained a virus or unwanted program 'EXP/2011-3544.FU' [exploit]
Action(s) taken:
The file was moved to the quarantine directory under the name '50623221.qua'! Hier FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Leo (ATTENTION: The logged in user is not administrator) on BAERENFROSCH on 21-03-2015 13:44:24
Running from C:\Users\Leo\Desktop
Loaded Profiles: Leo (Available profiles: Admin & Mama & Leo & MeinAdmin)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> OmniServ.exe
Failed to access process -> atiesrxx.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> hpservice.exe
Failed to access process -> RtkAudioService64.exe
Failed to access process -> svchost.exe
Failed to access process -> wlanext.exe
Failed to access process -> conhost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> Fuel.Service.exe
Failed to access process -> svchost.exe
Failed to access process -> mDNSResponder.exe
Failed to access process -> BTDevMgr.exe
Failed to access process -> DACore.exe
Failed to access process -> dasHost.exe
Failed to access process -> HPBDSService.exe
Failed to access process -> HPLaserJetService.exe
Failed to access process -> HPWMISVC.exe
Failed to access process -> LMIGuardianSvc.exe
Failed to access process -> svchost.exe
Failed to access process -> SynTPEnhService.exe
Failed to access process -> hamachi-2.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> WmiPrvSE.exe
Failed to access process -> dllhost.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> hpqwmiex.exe
Failed to access process -> GamesAppIntegrationService.exe
Failed to access process -> HPSA_Service.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> csrss.exe
Failed to access process -> winlogon.exe
Failed to access process -> dwm.exe
Failed to access process -> atieclxx.exe
Failed to access process -> RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
Failed to access process -> opvapp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16422_x64__8wekyb3d8bbwe\glcnd.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Pokki) C:\Users\Leo\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\Leo\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\Leo\AppData\Local\Pokki\Engine\StartMenuIndexer.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation) C:\Users\Leo\AppData\Local\Mozilla Firefox\firefox.exe
Failed to access process -> sched.exe
Failed to access process -> avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
Failed to access process -> avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
Failed to access process -> Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
Failed to access process -> svchost.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> SearchFilterHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7546072 2014-03-10] (Realtek Semiconductor)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3957816 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2818800 2014-04-22] (Synaptics Incorporated)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2014-10-31] (LogMeIn, Inc.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [126240 2014-02-13] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [475448 2014-03-04] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [313656 2013-04-18] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-02-17] (LogMeIn Inc.)
HKU\S-1-5-21-514103404-2733609734-414756415-1006\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1006\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
SearchScopes: HKLM -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-514103404-2733609734-414756415-1006 -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2015-01-10] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-01-10] (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-03-04] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-22] ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-01-10] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-01-10] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-22] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF SearchPlugin: C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\searchplugins\dictcc-de-en.xml [2014-11-19]
FF Extension: Avira Browser Safety - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\abs@avira.com [2015-03-10]
FF Extension: YouTube Unblocker - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\youtubeunblocker@unblocker.yt [2014-11-17]
FF Extension: Flash and Video Download - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2015-02-28]
FF Extension: YouTube mp3 - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\info@youtube-mp3.org.xpi [2014-11-17]
FF Extension: Dict.cc Translation - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\searchdictcc@roughael.xpi [2014-11-19]
FF Extension: The Addon Bar (restored) - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2015-01-22]
FF Extension: TinEye Reverse Image Search - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\tineye@ideeinc.com.xpi [2015-01-02]
FF Extension: Youtube HTML5 Video Player - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\youtube-video-player@lejenome.me.xpi [2015-01-22]
FF Extension: {56f9dc41-c7f3-4dd6-b691-1a1de6d07ba5} - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{56f9dc41-c7f3-4dd6-b691-1a1de6d07ba5}.xpi [2014-11-21]
FF Extension: Adblock Plus - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-01]
FF Extension: html helper - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{d113df31-25a7-44df-b6ab-bff7a10c157b}.xpi [2014-11-25]
StartMenuInternet: FIREFOX.EXE - C:\Users\Leo\AppData\Local\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR Profile: C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-07]
CHR Extension: (Google Drive) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-07]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-08]
CHR Extension: (YouTube) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-07]
CHR Extension: (Google Search) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-07]
CHR Extension: (Avira Browser Safety) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-03-09]
CHR Extension: (Google Wallet) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-07]
CHR Extension: (Gmail) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-07]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-21] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2015-01-23] ()
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [88064 2014-03-05] () [File not signed]
R2 DACoreService; C:\Program Files (x86)\Nuance\Dragon Notes\Core\DACore.exe [411024 2013-02-01] (Nuance Communications, Inc.)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-28] (WildTangent)
R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2011-10-17] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [174592 2012-12-04] (HP) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [469304 2014-03-04] (Hewlett-Packard Development Company, L.P.)
R2 lmhosts; C:\Windows\system32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [31552 2013-08-22] (Microsoft Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-02-16] (LogMeIn, Inc.)
S4 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [226152 2014-10-31] (LogMeIn, Inc.)
S4 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2014-10-31] (LogMeIn, Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [31552 2013-08-22] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [31552 2013-08-22] (Microsoft Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-01] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [191728 2014-04-22] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-11-04] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-12-20] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-02-17] (LogMeIn Inc.)
R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2014-10-31] (LogMeIn, Inc.)
S4 LMIRfsClientNP; No ImagePath
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-01-06] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3379416 2014-03-22] (Realtek Semiconductor Corporation )
R3 SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver_AMDASF.sys [30448 2014-04-22] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [31472 2014-04-22] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
S3 GENERICDRV; \??\C:\Users\ADMINI~1\AppData\Local\Temp\pftDAE8.tmp\amifldrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-21 13:44 - 2015-03-21 13:45 - 00020828 _____ () C:\Users\Leo\Desktop\FRST.txt
2015-03-21 13:44 - 2015-03-21 13:44 - 00000000 ____D () C:\FRST
2015-03-21 13:42 - 2015-03-21 13:42 - 02095616 _____ (Farbar) C:\Users\Leo\Desktop\FRST64.exe
2015-03-21 13:37 - 2015-03-21 13:37 - 00001418 _____ () C:\Users\Leo\Desktop\Events.txt
2015-03-12 02:00 - 2015-03-12 02:00 - 00002813 _____ () C:\Users\Leo\AppData\Local\recently-used.xbel
2015-03-06 14:07 - 2015-03-06 14:08 - 00000000 ____D () C:\Users\Leo\AppData\Local\Mozilla Firefox
2015-03-06 13:33 - 2015-03-06 13:34 - 02574000 _____ () C:\Users\Leo\Downloads\castle1.bsp
2015-03-06 10:37 - 2015-03-06 10:37 - 06758533 _____ () C:\Users\Leo\Downloads\KAS_0.4.10.zip
2015-03-06 10:34 - 2015-03-06 10:34 - 00043889 _____ () C:\Users\Leo\Downloads\targetron_1_3_4.zip
2015-03-06 10:30 - 2015-03-06 10:32 - 40723506 _____ () C:\Users\Leo\Downloads\Firespitter_634.zip
2015-03-06 10:27 - 2015-03-06 10:27 - 02368280 _____ () C:\Users\Leo\Downloads\Romfarer_LazorSystem_v35.zip
2015-03-06 10:24 - 2015-03-06 10:25 - 04325650 _____ () C:\Users\Leo\Downloads\MechJeb2-2.4.2.0.zip
2015-03-06 01:32 - 2015-03-06 01:38 - 00000000 ____D () C:\Users\Leo\workspace
2015-03-06 01:32 - 2015-03-06 01:32 - 00000000 ____D () C:\Users\Leo\AppData\Local\Eclipse
2015-03-06 01:29 - 2015-03-06 01:31 - 00000000 ____D () C:\Users\Leo\eclipse
2015-03-05 23:59 - 2015-03-05 23:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-03-05 23:59 - 2015-03-05 23:59 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2015-03-05 23:32 - 2015-03-05 23:40 - 162162770 _____ () C:\Users\Leo\eclipse-java-luna-SR2-win32-x86_64.zip
2015-03-01 20:22 - 2015-03-10 14:18 - 00043576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-03-01 20:21 - 2015-03-01 20:21 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\Avira
2015-03-01 20:05 - 2015-03-10 14:18 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-03-01 20:05 - 2015-03-10 14:18 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-03-01 20:05 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-03-01 19:58 - 2015-03-01 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-03-01 19:58 - 2015-03-01 19:58 - 00001226 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-03-01 19:57 - 2015-03-01 20:05 - 00000000 ____D () C:\ProgramData\Avira
2015-03-01 19:57 - 2015-03-01 20:05 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-03-01 17:30 - 2015-03-01 17:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\GeoGebra 5.0
2015-02-28 10:51 - 2015-02-28 10:51 - 00001712 _____ () C:\Users\Leo\Desktop\GeoGebra.lnk
2015-02-28 10:51 - 2015-02-28 10:51 - 00000000 ____D () C:\Users\Leo\GeoGebra 5.0
2015-02-28 10:51 - 2015-02-28 10:51 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GeoGebra 5
2015-02-22 11:09 - 2015-02-22 11:09 - 00000222 _____ () C:\Users\Leo\Desktop\HIT.url
2015-02-19 14:36 - 2015-02-19 14:36 - 00000000 ____D () C:\Users\Leo\AppData\Local\Steam
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-21 13:46 - 2014-10-01 19:21 - 00000000 ____D () C:\Users\Leo\AppData\Local\Pokki
2015-03-21 13:45 - 2014-11-07 23:31 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-21 13:44 - 2014-10-01 19:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\ClassicShell
2015-03-21 13:33 - 2014-10-01 19:23 - 00000000 ____D () C:\Users\Leo\Documents\Youcam
2015-03-21 13:30 - 2014-11-07 23:31 - 00001140 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-21 13:28 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-03-14 02:20 - 2014-10-01 18:18 - 01598778 _____ () C:\Windows\WindowsUpdate.log
2015-03-13 21:12 - 2014-10-01 19:31 - 00000000 ____D () C:\Users\MeinAdmin
2015-03-13 19:29 - 2015-01-18 14:28 - 00002338 _____ () C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-03-12 21:03 - 2014-10-01 19:21 - 00000000 ____D () C:\Users\Leo
2015-03-12 21:03 - 2014-10-01 19:14 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-03-12 20:48 - 2014-11-07 23:33 - 00002202 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-12 20:26 - 2014-04-30 23:19 - 00800954 _____ () C:\Windows\system32\perfh007.dat
2015-03-12 20:26 - 2014-04-30 23:19 - 00174458 _____ () C:\Windows\system32\perfc007.dat
2015-03-12 20:26 - 2014-03-18 10:53 - 01921154 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-12 20:19 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-12 01:58 - 2015-01-10 14:40 - 00000000 ____D () C:\Users\Leo\AppData\Local\gtk-2.0
2015-03-12 01:54 - 2015-01-10 14:33 - 00000000 ____D () C:\Users\Leo\.gimp-2.8
2015-03-12 01:51 - 2014-10-02 07:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\vlc
2015-03-11 00:51 - 2014-12-28 02:16 - 00000045 _____ () C:\Users\Leo\Documents\Isaac.txt
2015-03-08 20:58 - 2013-08-22 15:46 - 00032607 _____ () C:\Windows\setupact.log
2015-03-06 15:06 - 2014-10-02 14:43 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\TS3Client
2015-03-05 23:57 - 2014-03-18 10:44 - 00152934 _____ () C:\Windows\PFRO.log
2015-03-03 21:21 - 2014-10-05 22:13 - 00000000 ____D () C:\Spiele
2015-03-03 18:51 - 2014-06-10 20:41 - 00000000 ____D () C:\ProgramData\McAfee
2015-03-03 18:51 - 2014-06-10 20:41 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-03-01 20:26 - 2014-11-07 23:38 - 00000000 ____D () C:\Users\MeinAdmin\AppData\Roaming\ClassicShell
2015-03-01 19:57 - 2014-06-10 20:11 - 00000000 ____D () C:\ProgramData\Package Cache
2015-03-01 19:56 - 2013-08-22 16:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2015-03-01 19:55 - 2014-04-30 14:17 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-03-01 19:54 - 2015-02-07 13:58 - 00000000 ____D () C:\Users\Mama
2015-03-01 19:43 - 2014-11-07 23:33 - 00000000 ____D () C:\Users\Leo\AppData\Local\LogMeIn Hamachi
2015-02-22 15:35 - 2014-11-05 21:54 - 00261632 ___SH () C:\Users\Leo\Downloads\Thumbs.db
==================== Files in the root of some directories =======
2015-01-23 22:11 - 2015-01-23 22:11 - 1748552 _____ () C:\Users\Leo\AppData\Roaming\TheRCModDemo v3.0.1.1 [1.7.10].jar
2015-03-12 02:00 - 2015-03-12 02:00 - 0002813 _____ () C:\Users\Leo\AppData\Local\recently-used.xbel
Some content of TEMP:
====================
C:\Users\Leo\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll
C:\Users\Leo\AppData\Local\Temp\7941aa9f1a1ffb54e75f6abe950bcdb6.dll
C:\Users\Leo\AppData\Local\Temp\avgnt.exe
C:\Users\Leo\AppData\Local\Temp\COMAP.EXE
C:\Users\Leo\AppData\Local\Temp\ipyzdlw8.dll
C:\Users\Leo\AppData\Local\Temp\oct6287.tmp.exe
C:\Users\Leo\AppData\Local\Temp\octD4B.tmp.exe
C:\Users\Leo\AppData\Local\Temp\octE7D5.tmp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================ --- --- ---
--- --- ---
Und Addition:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Leo (ATTENTION: The logged in user is not administrator) on BAERENFROSCH on 21-03-2015 13:44:24
Running from C:\Users\Leo\Desktop
Loaded Profiles: Leo (Available profiles: Admin & Mama & Leo & MeinAdmin)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> OmniServ.exe
Failed to access process -> atiesrxx.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> hpservice.exe
Failed to access process -> RtkAudioService64.exe
Failed to access process -> svchost.exe
Failed to access process -> wlanext.exe
Failed to access process -> conhost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> Fuel.Service.exe
Failed to access process -> svchost.exe
Failed to access process -> mDNSResponder.exe
Failed to access process -> BTDevMgr.exe
Failed to access process -> DACore.exe
Failed to access process -> dasHost.exe
Failed to access process -> HPBDSService.exe
Failed to access process -> HPLaserJetService.exe
Failed to access process -> HPWMISVC.exe
Failed to access process -> LMIGuardianSvc.exe
Failed to access process -> svchost.exe
Failed to access process -> SynTPEnhService.exe
Failed to access process -> hamachi-2.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> WmiPrvSE.exe
Failed to access process -> dllhost.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> hpqwmiex.exe
Failed to access process -> GamesAppIntegrationService.exe
Failed to access process -> HPSA_Service.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> csrss.exe
Failed to access process -> winlogon.exe
Failed to access process -> dwm.exe
Failed to access process -> atieclxx.exe
Failed to access process -> RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
Failed to access process -> opvapp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.3.9600.16422_x64__8wekyb3d8bbwe\glcnd.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard Company) C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Pokki) C:\Users\Leo\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\Leo\AppData\Local\Pokki\Engine\HostAppService.exe
(Pokki) C:\Users\Leo\AppData\Local\Pokki\Engine\StartMenuIndexer.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Mozilla Corporation) C:\Users\Leo\AppData\Local\Mozilla Firefox\firefox.exe
Failed to access process -> sched.exe
Failed to access process -> avguard.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
Failed to access process -> avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
Failed to access process -> Avira.OE.ServiceHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
Failed to access process -> svchost.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> SearchFilterHost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7546072 2014-03-10] (Realtek Semiconductor)
HKLM\...\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [3957816 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [415288 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [415288 2014-03-01] (Hewlett-Packard)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2818800 2014-04-22] (Synaptics Incorporated)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161984 2014-04-20] (IvoSoft)
HKLM\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [57928 2014-10-31] (LogMeIn, Inc.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-04-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [126240 2014-02-13] (Hewlett-Packard Company)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [475448 2014-03-04] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [StatusAlerts] => C:\Program Files (x86)\HP\StatusAlerts\bin\HPStatusAlerts.exe [313656 2013-04-18] (Hewlett-Packard Company)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [704512 2015-03-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [3978600 2015-02-17] (LogMeIn Inc.)
HKU\S-1-5-21-514103404-2733609734-414756415-1006\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1006\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT14/4
HKU\S-1-5-21-514103404-2733609734-414756415-1006\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT14/4
SearchScopes: HKLM -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-514103404-2733609734-414756415-1006 -> {9CBE1607-B466-40F4-AB15-F6965BEA20A1} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll [2015-01-10] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-01-10] (Oracle Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-03-04] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-22] ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-01-10] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-01-10] (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-22] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-06] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-06] ()
FF SearchPlugin: C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\searchplugins\dictcc-de-en.xml [2014-11-19]
FF Extension: Avira Browser Safety - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\abs@avira.com [2015-03-10]
FF Extension: YouTube Unblocker - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\youtubeunblocker@unblocker.yt [2014-11-17]
FF Extension: Flash and Video Download - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2015-02-28]
FF Extension: YouTube mp3 - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\info@youtube-mp3.org.xpi [2014-11-17]
FF Extension: Dict.cc Translation - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\searchdictcc@roughael.xpi [2014-11-19]
FF Extension: The Addon Bar (restored) - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\the-addon-bar@GeekInTraining-GiT.xpi [2015-01-22]
FF Extension: TinEye Reverse Image Search - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\tineye@ideeinc.com.xpi [2015-01-02]
FF Extension: Youtube HTML5 Video Player - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\youtube-video-player@lejenome.me.xpi [2015-01-22]
FF Extension: {56f9dc41-c7f3-4dd6-b691-1a1de6d07ba5} - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{56f9dc41-c7f3-4dd6-b691-1a1de6d07ba5}.xpi [2014-11-21]
FF Extension: Adblock Plus - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-10-01]
FF Extension: html helper - C:\Users\Leo\AppData\Roaming\Mozilla\Firefox\Profiles\igepsb3l.default\Extensions\{d113df31-25a7-44df-b6ab-bff7a10c157b}.xpi [2014-11-25]
StartMenuInternet: FIREFOX.EXE - C:\Users\Leo\AppData\Local\Mozilla Firefox\firefox.exe
Chrome:
=======
CHR Profile: C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-07]
CHR Extension: (Google Drive) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-07]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-08]
CHR Extension: (YouTube) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-07]
CHR Extension: (Google Search) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-07]
CHR Extension: (Avira Browser Safety) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2015-03-09]
CHR Extension: (Google Wallet) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-07]
CHR Extension: (Gmail) - C:\Users\Leo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-07]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-06] (Advanced Micro Devices, Inc.) [File not signed]
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [432888 2015-03-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [432888 2015-03-21] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [448384 2015-01-23] ()
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [88064 2014-03-05] () [File not signed]
R2 DACoreService; C:\Program Files (x86)\Nuance\Dragon Notes\Core\DACore.exe [411024 2013-02-01] (Nuance Communications, Inc.)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-28] (WildTangent)
R2 HP DS Service; C:\Program Files (x86)\HP\HPBDSService\HPBDSService.exe [13824 2011-10-17] (Hewlett-Packard Company) [File not signed]
R2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [174592 2012-12-04] (HP) [File not signed]
R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2014-01-13] (Hewlett-Packard Company) [File not signed]
R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [469304 2014-03-04] (Hewlett-Packard Development Company, L.P.)
R2 lmhosts; C:\Windows\system32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [31552 2013-08-22] (Microsoft Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [417552 2015-02-16] (LogMeIn, Inc.)
S4 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [226152 2014-10-31] (LogMeIn, Inc.)
S4 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2014-10-31] (LogMeIn, Inc.)
R2 NlaSvc; C:\Windows\System32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [31552 2013-08-22] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [37768 2013-08-22] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [31552 2013-08-22] (Microsoft Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [88064 2014-03-01] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-08] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [191728 2014-04-22] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-04-02] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36608 2013-12-14] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-11-04] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [222720 2013-12-20] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-11-24] (Avira Operations GmbH & Co. KG)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-12] (CyberLink)
R3 Hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [44296 2015-02-17] (LogMeIn Inc.)
R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2014-10-31] (LogMeIn, Inc.)
S4 LMIRfsClientNP; No ImagePath
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [291544 2014-01-04] (Realtek Semiconductor Corp.)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [558296 2014-01-06] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3379416 2014-03-22] (Realtek Semiconductor Corporation )
R3 SmbDrv; C:\Windows\system32\DRIVERS\Smb_driver_AMDASF.sys [30448 2014-04-22] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [31472 2014-04-22] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-07-22] (Hewlett-Packard Development Company, L.P.)
S3 GENERICDRV; \??\C:\Users\ADMINI~1\AppData\Local\Temp\pftDAE8.tmp\amifldrv64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-21 13:44 - 2015-03-21 13:45 - 00020828 _____ () C:\Users\Leo\Desktop\FRST.txt
2015-03-21 13:44 - 2015-03-21 13:44 - 00000000 ____D () C:\FRST
2015-03-21 13:42 - 2015-03-21 13:42 - 02095616 _____ (Farbar) C:\Users\Leo\Desktop\FRST64.exe
2015-03-21 13:37 - 2015-03-21 13:37 - 00001418 _____ () C:\Users\Leo\Desktop\Events.txt
2015-03-12 02:00 - 2015-03-12 02:00 - 00002813 _____ () C:\Users\Leo\AppData\Local\recently-used.xbel
2015-03-06 14:07 - 2015-03-06 14:08 - 00000000 ____D () C:\Users\Leo\AppData\Local\Mozilla Firefox
2015-03-06 13:33 - 2015-03-06 13:34 - 02574000 _____ () C:\Users\Leo\Downloads\castle1.bsp
2015-03-06 10:37 - 2015-03-06 10:37 - 06758533 _____ () C:\Users\Leo\Downloads\KAS_0.4.10.zip
2015-03-06 10:34 - 2015-03-06 10:34 - 00043889 _____ () C:\Users\Leo\Downloads\targetron_1_3_4.zip
2015-03-06 10:30 - 2015-03-06 10:32 - 40723506 _____ () C:\Users\Leo\Downloads\Firespitter_634.zip
2015-03-06 10:27 - 2015-03-06 10:27 - 02368280 _____ () C:\Users\Leo\Downloads\Romfarer_LazorSystem_v35.zip
2015-03-06 10:24 - 2015-03-06 10:25 - 04325650 _____ () C:\Users\Leo\Downloads\MechJeb2-2.4.2.0.zip
2015-03-06 01:32 - 2015-03-06 01:38 - 00000000 ____D () C:\Users\Leo\workspace
2015-03-06 01:32 - 2015-03-06 01:32 - 00000000 ____D () C:\Users\Leo\AppData\Local\Eclipse
2015-03-06 01:29 - 2015-03-06 01:31 - 00000000 ____D () C:\Users\Leo\eclipse
2015-03-05 23:59 - 2015-03-05 23:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
2015-03-05 23:59 - 2015-03-05 23:59 - 00000000 ____D () C:\Program Files (x86)\LogMeIn Hamachi
2015-03-05 23:32 - 2015-03-05 23:40 - 162162770 _____ () C:\Users\Leo\eclipse-java-luna-SR2-win32-x86_64.zip
2015-03-01 20:22 - 2015-03-10 14:18 - 00043576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-03-01 20:21 - 2015-03-01 20:21 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\Avira
2015-03-01 20:05 - 2015-03-10 14:18 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-03-01 20:05 - 2015-03-10 14:18 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-03-01 20:05 - 2014-11-24 10:23 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-03-01 19:58 - 2015-03-01 20:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-03-01 19:58 - 2015-03-01 19:58 - 00001226 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-03-01 19:57 - 2015-03-01 20:05 - 00000000 ____D () C:\ProgramData\Avira
2015-03-01 19:57 - 2015-03-01 20:05 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-03-01 17:30 - 2015-03-01 17:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\GeoGebra 5.0
2015-02-28 10:51 - 2015-02-28 10:51 - 00001712 _____ () C:\Users\Leo\Desktop\GeoGebra.lnk
2015-02-28 10:51 - 2015-02-28 10:51 - 00000000 ____D () C:\Users\Leo\GeoGebra 5.0
2015-02-28 10:51 - 2015-02-28 10:51 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GeoGebra 5
2015-02-22 11:09 - 2015-02-22 11:09 - 00000222 _____ () C:\Users\Leo\Desktop\HIT.url
2015-02-19 14:36 - 2015-02-19 14:36 - 00000000 ____D () C:\Users\Leo\AppData\Local\Steam
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-21 13:46 - 2014-10-01 19:21 - 00000000 ____D () C:\Users\Leo\AppData\Local\Pokki
2015-03-21 13:45 - 2014-11-07 23:31 - 00001144 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-03-21 13:44 - 2014-10-01 19:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\ClassicShell
2015-03-21 13:33 - 2014-10-01 19:23 - 00000000 ____D () C:\Users\Leo\Documents\Youcam
2015-03-21 13:30 - 2014-11-07 23:31 - 00001140 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-03-21 13:28 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2015-03-14 02:20 - 2014-10-01 18:18 - 01598778 _____ () C:\Windows\WindowsUpdate.log
2015-03-13 21:12 - 2014-10-01 19:31 - 00000000 ____D () C:\Users\MeinAdmin
2015-03-13 19:29 - 2015-01-18 14:28 - 00002338 _____ () C:\Users\Leo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-03-12 21:03 - 2014-10-01 19:21 - 00000000 ____D () C:\Users\Leo
2015-03-12 21:03 - 2014-10-01 19:14 - 00000000 ____D () C:\Program Files (x86)\Steam
2015-03-12 20:48 - 2014-11-07 23:33 - 00002202 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-03-12 20:26 - 2014-04-30 23:19 - 00800954 _____ () C:\Windows\system32\perfh007.dat
2015-03-12 20:26 - 2014-04-30 23:19 - 00174458 _____ () C:\Windows\system32\perfc007.dat
2015-03-12 20:26 - 2014-03-18 10:53 - 01921154 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-12 20:19 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-12 01:58 - 2015-01-10 14:40 - 00000000 ____D () C:\Users\Leo\AppData\Local\gtk-2.0
2015-03-12 01:54 - 2015-01-10 14:33 - 00000000 ____D () C:\Users\Leo\.gimp-2.8
2015-03-12 01:51 - 2014-10-02 07:30 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\vlc
2015-03-11 00:51 - 2014-12-28 02:16 - 00000045 _____ () C:\Users\Leo\Documents\Isaac.txt
2015-03-08 20:58 - 2013-08-22 15:46 - 00032607 _____ () C:\Windows\setupact.log
2015-03-06 15:06 - 2014-10-02 14:43 - 00000000 ____D () C:\Users\Leo\AppData\Roaming\TS3Client
2015-03-05 23:57 - 2014-03-18 10:44 - 00152934 _____ () C:\Windows\PFRO.log
2015-03-03 21:21 - 2014-10-05 22:13 - 00000000 ____D () C:\Spiele
2015-03-03 18:51 - 2014-06-10 20:41 - 00000000 ____D () C:\ProgramData\McAfee
2015-03-03 18:51 - 2014-06-10 20:41 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-03-01 20:26 - 2014-11-07 23:38 - 00000000 ____D () C:\Users\MeinAdmin\AppData\Roaming\ClassicShell
2015-03-01 19:57 - 2014-06-10 20:11 - 00000000 ____D () C:\ProgramData\Package Cache
2015-03-01 19:56 - 2013-08-22 16:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2015-03-01 19:55 - 2014-04-30 14:17 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-03-01 19:54 - 2015-02-07 13:58 - 00000000 ____D () C:\Users\Mama
2015-03-01 19:43 - 2014-11-07 23:33 - 00000000 ____D () C:\Users\Leo\AppData\Local\LogMeIn Hamachi
2015-02-22 15:35 - 2014-11-05 21:54 - 00261632 ___SH () C:\Users\Leo\Downloads\Thumbs.db
==================== Files in the root of some directories =======
2015-01-23 22:11 - 2015-01-23 22:11 - 1748552 _____ () C:\Users\Leo\AppData\Roaming\TheRCModDemo v3.0.1.1 [1.7.10].jar
2015-03-12 02:00 - 2015-03-12 02:00 - 0002813 _____ () C:\Users\Leo\AppData\Local\recently-used.xbel
Some content of TEMP:
====================
C:\Users\Leo\AppData\Local\Temp\4c2459bebc146bfd821d90e28a2411ab.dll
C:\Users\Leo\AppData\Local\Temp\7941aa9f1a1ffb54e75f6abe950bcdb6.dll
C:\Users\Leo\AppData\Local\Temp\avgnt.exe
C:\Users\Leo\AppData\Local\Temp\COMAP.EXE
C:\Users\Leo\AppData\Local\Temp\ipyzdlw8.dll
C:\Users\Leo\AppData\Local\Temp\oct6287.tmp.exe
C:\Users\Leo\AppData\Local\Temp\octD4B.tmp.exe
C:\Users\Leo\AppData\Local\Temp\octE7D5.tmp.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================ --- --- ---
--- --- --- |