Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Update, 03.05.2015 00:06:57, SYSTEM, ADRIAN, Scheduler, Malware Database, 2015.5.2.4, 2015.5.2.5,
Protection, 03.05.2015 00:06:57, SYSTEM, ADRIAN, Protection, Refresh, Starting,
Protection, 03.05.2015 00:06:57, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopping,
Protection, 03.05.2015 00:06:57, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopped,
Protection, 03.05.2015 00:09:04, SYSTEM, ADRIAN, Protection, Refresh, Success,
Protection, 03.05.2015 00:09:04, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Starting,
Protection, 03.05.2015 00:09:04, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Started,
Update, 03.05.2015 01:00:40, SYSTEM, ADRIAN, Scheduler, Malware Database, 2015.5.2.5, 2015.5.2.6,
Protection, 03.05.2015 01:00:40, SYSTEM, ADRIAN, Protection, Refresh, Starting,
Protection, 03.05.2015 01:00:40, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopping,
Protection, 03.05.2015 01:00:40, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopped,
Protection, 03.05.2015 01:02:57, SYSTEM, ADRIAN, Protection, Refresh, Success,
Protection, 03.05.2015 01:02:57, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Starting,
Protection, 03.05.2015 01:02:58, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Started,
Update, 03.05.2015 10:53:31, SYSTEM, ADRIAN, Scheduler, Malware Database, 2015.5.2.6, 2015.5.3.2,
Protection, 03.05.2015 10:53:32, SYSTEM, ADRIAN, Protection, Refresh, Starting,
Protection, 03.05.2015 10:53:32, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopping,
Protection, 03.05.2015 10:53:32, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopped,
Protection, 03.05.2015 10:56:20, SYSTEM, ADRIAN, Protection, Refresh, Success,
Protection, 03.05.2015 10:56:45, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Starting,
Protection, 03.05.2015 10:56:45, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Started,
Detection, 03.05.2015 11:29:20, SYSTEM, ADRIAN, Protection, Malicious Website Protection, IP, 193.107.16.221, canna.to, 56350, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe,
Detection, 03.05.2015 11:29:20, SYSTEM, ADRIAN, Protection, Malicious Website Protection, IP, 193.107.16.221, canna.to, 56350, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe,
Detection, 03.05.2015 11:29:54, SYSTEM, ADRIAN, Protection, Malicious Website Protection, IP, 193.107.16.221, uu.canna.to, 56447, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe,
Detection, 03.05.2015 11:29:54, SYSTEM, ADRIAN, Protection, Malicious Website Protection, IP, 193.107.16.221, uu.canna.to, 56447, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe,
Detection, 03.05.2015 11:30:14, SYSTEM, ADRIAN, Protection, Malicious Website Protection, IP, 193.107.16.221, canna.to, 56503, Outbound, C:\Program Files (x86)\Mozilla Firefox\firefox.exe,
Update, 03.05.2015 14:23:36, SYSTEM, ADRIAN, Scheduler, Malware Database, 2015.5.3.2, 2015.5.3.3,
Protection, 03.05.2015 14:23:36, SYSTEM, ADRIAN, Protection, Refresh, Starting,
Protection, 03.05.2015 14:23:36, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopping,
Protection, 03.05.2015 14:23:39, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Stopped,
Protection, 03.05.2015 14:26:26, SYSTEM, ADRIAN, Protection, Refresh, Success,
Protection, 03.05.2015 14:26:26, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Starting,
Protection, 03.05.2015 14:26:26, SYSTEM, ADRIAN, Protection, Malicious Website Protection, Started,
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v4.203 - Bericht erstellt 03/05/2015 um 14:58:27
# Aktualisiert 30/04/2015 von Xplode
# Datenbank : 2015-05-02.1 [Server]
# Betriebssystem : Windows 8.1 Pro (x64)
# Benutzername : Adrian - ADRIAN
# Gestarted von : C:\Users\Adrian\Downloads\adwcleaner_4.203.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v37.0.1 (x86 de)
[P387JiKR.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "chrome://unitedtb/content/newtab/newtab-page.xhtml");
-\\ Google Chrome v42.0.2311.135
*************************
AdwCleaner[R0].txt - [4637 Bytes] - [19/04/2015 20:04:37]
AdwCleaner[R10].txt - [1881 Bytes] - [03/05/2015 14:57:10]
AdwCleaner[R1].txt - [4696 Bytes] - [19/04/2015 20:10:15]
AdwCleaner[R2].txt - [987 Bytes] - [19/04/2015 20:16:44]
AdwCleaner[R3].txt - [1132 Bytes] - [27/04/2015 22:04:02]
AdwCleaner[R4].txt - [1163 Bytes] - [27/04/2015 22:06:13]
AdwCleaner[R5].txt - [1620 Bytes] - [01/05/2015 15:20:25]
AdwCleaner[R6].txt - [1401 Bytes] - [01/05/2015 15:29:34]
AdwCleaner[R7].txt - [1460 Bytes] - [01/05/2015 22:00:50]
AdwCleaner[R8].txt - [1792 Bytes] - [02/05/2015 04:36:20]
AdwCleaner[R9].txt - [1762 Bytes] - [02/05/2015 04:42:29]
AdwCleaner[S0].txt - [4143 Bytes] - [19/04/2015 20:11:32]
AdwCleaner[S1].txt - [524 Bytes] - [27/04/2015 22:05:31]
AdwCleaner[S2].txt - [1223 Bytes] - [27/04/2015 22:07:29]
AdwCleaner[S3].txt - [1679 Bytes] - [01/05/2015 15:22:31]
AdwCleaner[S4].txt - [879 Bytes] - [02/05/2015 04:37:37]
AdwCleaner[S5].txt - [1830 Bytes] - [02/05/2015 04:43:51]
AdwCleaner[S6].txt - [1810 Bytes] - [03/05/2015 14:58:27]
########## EOF - C:\AdwCleaner\AdwCleaner[S6].txt - [1869 Bytes] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.6.7 (04.30.2015:1)
OS: Windows 8.1 Pro x64
Ran by Adrian on 03.05.2015 at 15:06:04,18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Adrian\AppData\Roaming\mozilla\firefox\profiles\P387JiKR.default\extensions\toolbar@web.de
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.05.2015 at 15:09:13,03
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-05-2015
Ran by Adrian (administrator) on ADRIAN on 03-05-2015 15:10:18
Running from C:\Users\Adrian\Downloads
Loaded Profiles: Adrian (Available profiles: Adrian)
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NVRaidService] => C:\WINDOWS\system32\nvraidservice.exe [291872 2009-06-30] (NVIDIA Corporation)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169768 2015-04-07] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-01] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310064 2014-06-14] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767200 2014-09-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1361987400-3057646630-3455327573-1002\...\Run: [AviraSpeedup] => "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
HKU\S-1-5-21-1361987400-3057646630-3455327573-1002\...\Run: [EADM] => D:\Program Files (x86)\Origin\Origin.exe [3632472 2015-04-13] (Electronic Arts)
HKU\S-1-5-21-1361987400-3057646630-3455327573-1002\...\MountPoints2: {3721ac85-eca6-11e3-8254-0023548c8077} - "J:\setup.exe"
HKU\S-1-5-21-1361987400-3057646630-3455327573-1002\...\MountPoints2: {d2622432-4af9-11e4-825d-0023548c8077} - "K:\setup.exe"
HKU\S-1-5-18\...\Run: [AviraSpeedup] => "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
Startup: C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-04-09]
ShortcutTarget: Dropbox.lnk -> C:\Users\Adrian\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar571.lnk [2015-04-27]
ShortcutTarget: Sidebar571.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (No File)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Adrian\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-11] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\S-1-5-21-1361987400-3057646630-3455327573-1002\Software\Microsoft\Internet Explorer\Main,Start Page = Google
HKU\S-1-5-21-1361987400-3057646630-3455327573-1002\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Deutschland ? mit Hotmail Nachfolger Outlook und Messenger Skype
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-18] (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-18] (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-10-15] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{58F336D0-23FB-40DC-8FC7-267CA32F5FE1}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\P387JiKR.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-14] ()
FF Plugin: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelogx64.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelogx64.dll [2014-12-03] (EA Digital Illusions CE AB)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-14] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @esn/npbattlelog,version=2.5.1 -> C:\Program Files (x86)\Battlelog Web Plugins\2.5.1\npbattlelog.dll [2014-09-01] (EA Digital Illusions CE AB)
FF Plugin-x32: @esn/npbattlelog,version=2.6.2 -> C:\Program Files (x86)\Battlelog Web Plugins\2.6.2\npbattlelog.dll [2014-12-03] (EA Digital Illusions CE AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-03-31] (Microsoft Corporation)
FF Extension: Avira Browser Safety - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\P387JiKR.default\Extensions\abs@avira.com [2015-05-03]
FF Extension: FT DeepDark - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\P387JiKR.default\Extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66} [2015-05-03]
FF Extension: NASA Night Launch - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\P387JiKR.default\Extensions\nasanightlaunch@example.com.xpi [2015-04-10]
FF Extension: Adblock Plus - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\P387JiKR.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-10]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: No Name - C:\Users\Adrian\AppData\Roaming\Mozilla\Firefox\Profiles\P387JiKR.default\extensions\toolbar@web.de [Not Found]
Chrome:
=======
CHR Profile: C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Adblock Plus) - C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-24]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\Adrian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-23]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-09-15] (Advanced Micro Devices, Inc.) [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-04-01] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-01] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-01] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-20] (Apple Inc.)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S2 MBAMScheduler; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; D:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S3 Origin Client Service; D:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-13] (Electronic Arts)
S2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [76152 2015-03-19] ()
S2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76888 2015-03-19] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R2 AODDriver4.1; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [223232 2014-06-21] (Advanced Micro Devices)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-03-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-08-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-03-04] (Avira Operations GmbH & Co. KG)
S3 CM_VENDER_CMD; C:\Program Files\Common Files\Logitech\G430Install\CMVC64.sys [17104 2014-07-31] (Windows (R) Win 7 DDK provider)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-05-03] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-04-14] (Malwarebytes Corporation)
R0 nvrd64; C:\Windows\System32\DRIVERS\nvrd64.sys [175648 2009-08-04] (NVIDIA Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 xusb22; C:\Windows\System32\drivers\xusb22.sys [87040 2014-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-03 15:09 - 2015-05-03 15:09 - 00000747 _____ () C:\Users\Adrian\Desktop\JRT.txt
2015-05-03 15:03 - 2015-05-03 15:03 - 00000207 _____ () C:\WINDOWS\tweaking.com-regbackup-ADRIAN-Windows-8.1-Pro-(64-bit).dat
2015-05-03 15:03 - 2015-05-03 15:03 - 00000000 ____D () C:\RegBackup
2015-05-03 15:02 - 2015-05-03 14:57 - 02716306 _____ (Thisisu) C:\Users\Adrian\Desktop\JRT.exe
2015-05-03 14:57 - 2015-05-03 14:57 - 02716306 _____ (Thisisu) C:\Users\Adrian\Downloads\JRT.exe
2015-05-03 14:55 - 2015-05-03 14:55 - 00003713 _____ () C:\Users\Adrian\Desktop\mbam.txt
2015-05-03 13:01 - 2015-05-03 13:03 - 47347406 _____ () C:\Users\Adrian\Downloads\FH16_2013_v18.4.5s_ohaha.rar
2015-05-03 01:36 - 2015-05-03 01:36 - 01057526 _____ () C:\Users\Adrian\Downloads\Kings heavy haulage Volvo2.rar
2015-05-03 00:52 - 2015-05-03 00:53 - 00047885 _____ () C:\Users\Adrian\Downloads\Addition.txt
2015-05-03 00:50 - 2015-05-03 15:10 - 00016230 _____ () C:\Users\Adrian\Downloads\FRST.txt
2015-05-03 00:50 - 2015-05-03 15:10 - 00000000 ____D () C:\FRST
2015-05-03 00:49 - 2015-05-03 00:50 - 02101248 _____ (Farbar) C:\Users\Adrian\Downloads\FRST64.exe
2015-05-02 23:41 - 2015-05-02 23:43 - 06386570 _____ () C:\Users\Adrian\Downloads\LS_15_TimTra207_V2_1.zip
2015-05-02 19:19 - 2015-05-03 15:04 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-05-02 19:19 - 2015-05-02 19:19 - 00000825 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-05-02 19:19 - 2015-05-02 19:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-05-02 19:19 - 2015-05-02 19:19 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-05-02 19:19 - 2015-04-14 09:38 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-05-02 19:19 - 2015-04-14 09:37 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-05-02 19:19 - 2015-04-14 09:37 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-05-02 19:17 - 2015-05-02 19:18 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\Adrian\Downloads\mbam-setup-2.1.6.1022.exe
2015-05-02 13:54 - 2015-05-02 14:18 - 348825232 _____ (GIANTS Software ) C:\Users\Adrian\Downloads\FarmingSimulator2015Patch1.3DE_PublicBeta1.exe
2015-05-02 02:55 - 2015-05-02 02:55 - 00000000 _____ () C:\autoexec.bat
2015-05-02 02:51 - 2015-05-02 02:51 - 03109248 _____ (Enigma Software Group USA, LLC.) C:\Users\Adrian\Downloads\SpyHunter-Installer.exe
2015-05-01 23:47 - 2015-05-01 23:47 - 00000804 _____ () C:\Users\Adrian\Desktop\Cheat Engine.lnk
2015-05-01 23:47 - 2015-05-01 23:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.4
2015-05-01 23:46 - 2015-05-01 23:46 - 09052432 _____ (Cheat Engine ) C:\Users\Adrian\Downloads\CheatEngine64.exe
2015-05-01 22:44 - 2015-05-01 22:44 - 00003162 _____ () C:\WINDOWS\System32\Tasks\{35ABDBFB-F2F4-4CF7-9AEE-7BF1EE7F8B9D}
2015-05-01 22:37 - 2003-08-04 10:19 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3a.dll
2015-05-01 22:35 - 2015-05-01 22:35 - 01203488 _____ () C:\Users\Adrian\Downloads\Virus Killer - CHIP-Installer.exe
2015-05-01 22:23 - 2015-05-01 22:23 - 04928032 _____ (AVG Technologies) C:\Users\Adrian\Downloads\avg_isc_stb_all_2015_ltst_206.exe
2015-05-01 19:31 - 2015-05-01 19:31 - 05081042 _____ () C:\Users\Adrian\Downloads\Trailer Standalone Chereau Vogel.rar
2015-05-01 19:30 - 2015-05-01 19:35 - 21476219 _____ () C:\Users\Adrian\Downloads\DAF XF 105.510 2 trucks.rar
2015-05-01 17:53 - 2015-05-01 17:54 - 03612760 _____ (Facebook Inc.) C:\Users\Adrian\Downloads\ESET_T679481662179459T_.exe
2015-05-01 15:19 - 2015-05-01 15:20 - 02204160 _____ () C:\Users\Adrian\Downloads\adwcleaner_4.203.exe
2015-04-30 15:05 - 2015-04-30 15:11 - 71971596 _____ () C:\Users\Adrian\Downloads\ETS 2 - Alcoa Jant Lastik.scs
2015-04-28 19:10 - 2015-04-28 19:10 - 00310232 _____ () C:\WINDOWS\Minidump\042815-34078-01.dmp
2015-04-28 18:32 - 2015-04-28 18:32 - 07066437 _____ () C:\Users\Adrian\Downloads\[powerkasi]custom_sideskirts_v0.6.scs
2015-04-28 18:31 - 2015-04-28 18:31 - 19075209 _____ () C:\Users\Adrian\Downloads\CSZ_set_by_DD_ModPassion_and_zBlacklion.zip
2015-04-28 15:40 - 2015-04-28 15:40 - 00338450 _____ () C:\Users\Adrian\Downloads\46054c-NativeTrainerandNorthYankton.rar
2015-04-28 15:40 - 2015-04-28 15:40 - 00224351 _____ () C:\Users\Adrian\Downloads\ScriptHookV.zip
2015-04-27 22:03 - 2015-04-27 22:03 - 02224640 _____ () C:\Users\Adrian\Downloads\adwcleaner_4.202.exe
2015-04-27 22:01 - 2015-04-27 22:01 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Sidebar7
2015-04-27 21:54 - 2015-04-27 21:55 - 05789051 _____ () C:\Users\Adrian\Downloads\StimechFMP500 (1).zip
2015-04-21 21:48 - 2015-05-02 14:46 - 00000080 _____ () C:\Users\Adrian\AppData\Local剜捯獫慴慇敭屳呇⁁屖湥楴汴浥湥湩潦
2015-04-21 21:48 - 2015-04-21 21:48 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Rockstar Games
2015-04-21 21:46 - 2015-04-21 21:51 - 00000000 ____D () C:\Users\Adrian\Documents\Rockstar Games
2015-04-21 21:46 - 2015-04-21 21:51 - 00000000 ____D () C:\Program Files (x86)\Rockstar Games
2015-04-21 21:45 - 2015-04-21 21:51 - 00000000 ____D () C:\Program Files\Rockstar Games
2015-04-21 21:42 - 2015-04-21 21:42 - 00001045 _____ () C:\Users\Public\Desktop\Grand Theft Auto V.lnk
2015-04-21 21:42 - 2015-04-21 21:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
2015-04-20 20:43 - 2015-04-20 20:44 - 13787758 _____ () C:\Users\Adrian\Downloads\ETS2_TZ_containers_trailer-(1.10.1).rar
2015-04-19 20:04 - 2015-05-03 14:58 - 00000000 ____D () C:\AdwCleaner
2015-04-18 10:37 - 2015-04-18 10:37 - 00246025 _____ () C:\Users\Adrian\Downloads\Trailer.rar
2015-04-16 22:13 - 2015-04-16 22:13 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-04-16 16:41 - 2015-03-23 23:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-04-16 16:41 - 2015-03-23 23:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-04-16 16:41 - 2015-03-23 23:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-04-16 16:41 - 2015-03-23 23:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-04-16 16:41 - 2015-03-23 23:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-04-16 16:41 - 2015-03-20 06:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2015-04-16 16:41 - 2015-03-20 06:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-04-16 16:41 - 2015-03-20 06:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-04-16 16:41 - 2015-03-20 05:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-04-16 16:41 - 2015-03-20 04:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-04-16 16:41 - 2015-03-20 04:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-04-16 16:41 - 2015-03-20 04:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-04-16 16:41 - 2015-03-14 10:20 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-04-16 16:41 - 2015-03-14 10:13 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-04-16 16:41 - 2015-02-21 01:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2015-04-16 16:40 - 2015-03-13 04:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2015-04-16 16:40 - 2015-03-13 04:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2015-04-15 21:51 - 2015-03-13 06:32 - 24980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-04-15 21:51 - 2015-03-13 06:08 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-04-15 21:51 - 2015-03-13 06:07 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-04-15 21:51 - 2015-03-13 05:53 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-04-15 21:51 - 2015-03-13 05:50 - 06025216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-04-15 21:51 - 2015-03-13 05:42 - 19695616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-04-15 21:51 - 2015-03-13 05:28 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-04-15 21:51 - 2015-03-13 05:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-04-15 21:51 - 2015-03-13 05:22 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-04-15 21:51 - 2015-03-13 05:17 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-04-15 21:51 - 2015-03-13 05:16 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-04-15 21:51 - 2015-03-13 05:08 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-04-15 21:51 - 2015-03-13 05:07 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-04-15 21:51 - 2015-03-13 05:00 - 14397440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-04-15 21:51 - 2015-03-13 04:50 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-04-15 21:51 - 2015-03-13 04:49 - 04305408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-04-15 21:51 - 2015-03-13 04:45 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-04-15 21:51 - 2015-03-13 04:44 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-04-15 21:51 - 2015-03-13 04:34 - 12825600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-04-15 21:51 - 2015-03-13 04:33 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-04-15 21:51 - 2015-03-13 04:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-04-15 21:51 - 2015-03-13 04:20 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-04-15 21:51 - 2015-03-13 04:16 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-04-15 21:51 - 2015-03-13 04:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-04-15 21:40 - 2015-02-24 10:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-04-15 21:37 - 2015-03-23 00:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-04-15 21:37 - 2015-03-23 00:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-04-15 21:37 - 2015-03-23 00:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-04-15 21:37 - 2015-03-23 00:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-04-15 21:37 - 2015-03-23 00:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-04-15 21:37 - 2015-03-23 00:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-04-15 21:37 - 2015-03-23 00:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-04-15 21:37 - 2015-03-14 10:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-04-15 21:37 - 2015-03-14 03:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-04-15 21:37 - 2015-03-14 03:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-04-15 21:37 - 2015-03-14 03:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-04-15 21:37 - 2015-03-14 03:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-04-15 21:37 - 2015-03-14 03:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-04-15 21:37 - 2015-03-14 02:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-04-15 21:37 - 2015-03-14 02:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-04-15 21:37 - 2015-03-14 02:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-04-15 21:37 - 2015-03-14 02:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-04-15 21:37 - 2015-03-14 02:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-04-15 21:37 - 2015-03-14 02:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-04-15 21:37 - 2015-03-14 02:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-04-15 21:37 - 2015-03-14 02:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-04-15 21:37 - 2015-03-14 02:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-04-15 21:37 - 2015-03-14 02:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-04-15 21:37 - 2015-03-14 01:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-04-15 21:37 - 2015-03-14 01:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-04-15 21:37 - 2015-03-04 12:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-04-15 21:37 - 2015-03-04 05:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-04-15 21:37 - 2015-03-04 04:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-04-15 21:37 - 2014-12-03 01:09 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-04-14 17:43 - 2015-04-14 17:46 - 56809290 _____ () C:\Users\Adrian\Downloads\FS15_newHollandCR_Pack.zip
2015-04-14 15:06 - 2015-04-14 15:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-04-11 15:10 - 2015-04-11 15:10 - 00001765 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-04-11 15:10 - 2015-04-11 15:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-04-11 15:10 - 2015-04-11 15:10 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-04-11 15:10 - 2015-04-11 15:10 - 00000000 ____D () C:\Program Files\iTunes
2015-04-11 15:10 - 2015-04-11 15:10 - 00000000 ____D () C:\Program Files\iPod
2015-04-11 15:10 - 2015-04-11 15:10 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-04-10 02:47 - 2015-04-10 02:47 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Macromedia
2015-04-10 02:33 - 2015-04-10 02:33 - 00001175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-10 02:33 - 2015-04-10 02:33 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-10 02:33 - 2015-04-10 02:33 - 00000000 ____D () C:\Users\Adrian\AppData\Local\Mozilla
2015-04-10 02:33 - 2015-04-10 02:33 - 00000000 ____D () C:\ProgramData\Mozilla
2015-04-10 02:33 - 2015-04-10 02:33 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-04-10 02:31 - 2015-04-10 02:31 - 00243656 _____ () C:\Users\Adrian\Downloads\Firefox Setup Stub 37.0.1.exe
2015-04-10 00:54 - 2015-04-10 00:56 - 22906956 _____ () C:\Users\Adrian\Downloads\Kuhn_Profile_Pack.zip
2015-04-08 20:27 - 2015-04-08 20:27 - 00009531 _____ () C:\Users\Adrian\Downloads\[www.OldSchoolHack.de]_Rei [00] - Advanced Warfare [1.4.1124420].zip
2015-04-08 20:25 - 2015-04-08 20:25 - 00111136 _____ () C:\Users\Adrian\Downloads\[www.OldSchoolHack.de]_AW Unlock Tool By Whysodifficult v2.zip
2015-04-08 20:24 - 2015-04-08 20:24 - 00623512 _____ () C:\Users\Adrian\Downloads\[www.OldSchoolHack.de]_SeNsoR Advanced Wafare Tool v1.5 (1).rar
2015-04-08 20:22 - 2015-04-08 20:23 - 00648036 _____ () C:\Users\Adrian\Downloads\[www.OldSchoolHack.de]_AW_VT.rar
2015-04-08 20:21 - 2015-04-08 20:21 - 06357043 _____ () C:\Users\Adrian\Downloads\Call-of-Duty-Advanced-Warfare-Trainer-Hack.rar
2015-04-08 20:14 - 2015-04-08 20:16 - 05168133 _____ () C:\Users\Adrian\Downloads\CoD AW ESP WH AIMBOT PRESTIGEHACK.rar
2015-04-08 19:53 - 2015-04-08 19:53 - 00047746 _____ () C:\Users\Adrian\Downloads\[www.OldSchoolHack.de]_UAV & WALL HACK.rar
2015-04-08 19:15 - 2015-04-08 19:17 - 52115698 _____ () C:\Users\Adrian\Downloads\Kenworth_T800_for_kriechbaum_v1.rar
2015-04-08 19:11 - 2015-04-08 19:11 - 03627364 _____ () C:\Users\Adrian\Downloads\B62-DELL_T800_PACK.zip
2015-04-08 18:03 - 2015-04-08 18:04 - 00623512 _____ () C:\Users\Adrian\Downloads\[www.OldSchoolHack.de]_SeNsoR Advanced Wafare Tool v1.5.rar
2015-04-08 17:38 - 2015-04-08 17:38 - 00096863 _____ () C:\Users\Adrian\Downloads\[www.OldSchoolHack.de]_Elite_Weapon_V1.rar
2015-04-08 13:33 - 2015-04-08 13:33 - 05789051 _____ () C:\Users\Adrian\Downloads\StimechFMP500.zip
2015-04-07 23:57 - 2015-04-07 23:57 - 00037940 _____ () C:\Users\Adrian\Downloads\ZZZ_complexBGA (1).zip
2015-04-07 03:05 - 2015-04-07 03:05 - 00712169 _____ () C:\Users\Adrian\Downloads\Light_Addon.zip
2015-04-06 18:59 - 2015-04-06 19:00 - 25426275 _____ () C:\Users\Adrian\Downloads\Ponsee_Wolverine.zip
2015-04-06 17:13 - 2015-04-06 17:23 - 159478016 _____ (GIANTS Software GmbH) C:\Users\Adrian\Downloads\FarmingSimulator15_jcbPack_v1.0.0.exe
2015-04-06 15:59 - 2015-04-06 16:04 - 77527560 _____ () C:\Users\Adrian\Downloads\akcesoria_do_tuningu_(02.11.14).rar
2015-04-06 14:30 - 2015-04-06 14:31 - 08802118 _____ () C:\Users\Adrian\Downloads\placeable_BaustellenabsicherungsSetV2_byNick981.zip
2015-04-05 22:59 - 2015-04-05 22:59 - 04157460 _____ () C:\Users\Adrian\Downloads\teamspeak3-server_win32-3.0.11.2.zip
2015-04-05 22:35 - 2015-05-01 03:24 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\TS3Client
2015-04-05 22:35 - 2015-04-05 22:35 - 00001106 _____ () C:\Users\Adrian\Desktop\TeamSpeak 3 Client.lnk
2015-04-05 22:35 - 2015-04-05 22:35 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2015-04-05 22:33 - 2015-04-05 22:34 - 28115400 _____ (TeamSpeak Systems GmbH) C:\Users\Adrian\Downloads\TeamSpeak3-Client-win32-3.0.16.exe
2015-04-05 21:59 - 2015-04-05 22:26 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Battlefield 4
2015-04-05 21:45 - 2015-04-05 21:47 - 30014480 _____ (TeamSpeak Systems GmbH) C:\Users\Adrian\Downloads\TeamSpeak3-Client-win64-3.0.16.exe
2015-04-04 15:44 - 2015-04-04 15:44 - 00347749 _____ () C:\Users\Adrian\Downloads\Rockstar_Energy_Scania_Streamline_by_SpyHanz.scs
2015-04-04 12:58 - 2015-04-04 12:58 - 00000000 ___SD () C:\WINDOWS\SysWOW64\GWX
2015-04-04 12:58 - 2015-04-04 12:58 - 00000000 ___SD () C:\WINDOWS\system32\GWX
2015-04-03 18:16 - 2015-04-03 18:16 - 00000565 _____ () C:\Users\Adrian\Downloads\horizon-setup (2).website
2015-04-03 18:16 - 2015-04-03 18:16 - 00000565 _____ () C:\Users\Adrian\Downloads\horizon-setup (1).website
2015-04-03 18:11 - 2015-04-03 18:11 - 00176166 _____ () C:\Users\Adrian\Downloads\GTA 5 All Main Characters Modded Money.rar
2015-04-03 18:10 - 2015-04-03 18:12 - 00000565 _____ () C:\Users\Adrian\Downloads\horizon-setup.website
2015-04-03 14:29 - 2015-04-03 14:29 - 06148525 _____ () C:\Users\Adrian\Downloads\Andreas_Schubert_Sonnenblende.scs
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-03 15:03 - 2015-02-05 21:45 - 00000000 ___RD () C:\Users\Adrian\Dropbox
2015-05-03 15:03 - 2014-08-14 13:46 - 01744111 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-03 15:02 - 2015-02-05 21:40 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Dropbox
2015-05-03 15:01 - 2015-01-08 22:53 - 00000000 ____D () C:\Users\Adrian\OneDrive
2015-05-03 15:01 - 2014-10-29 20:07 - 00000000 ____D () C:\ProgramData\Origin
2015-05-03 15:00 - 2014-08-14 13:57 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-05-03 14:59 - 2014-10-03 14:09 - 00104471 _____ () C:\WINDOWS\setupact.log
2015-05-03 14:59 - 2014-10-02 14:42 - 00243446 _____ () C:\WINDOWS\PFRO.log
2015-05-03 14:59 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-03 14:59 - 2013-08-22 15:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-03 14:35 - 2014-09-13 23:59 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-05-03 14:18 - 2014-08-14 13:57 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-05-03 14:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-03 13:23 - 2014-08-15 19:04 - 00000000 ____D () C:\Users\Adrian\Documents\Euro Truck Simulator 2
2015-05-03 13:01 - 2014-06-01 19:18 - 00000000 ____D () C:\Users\Adrian\Desktop\ETS2
2015-05-02 19:49 - 2014-08-14 14:03 - 00000000 ____D () C:\Users\Adrian\AppData\Local\ICSharpCode.net
2015-05-02 14:20 - 2014-10-30 15:57 - 00000978 _____ () C:\Users\Adrian\Desktop\Landwirtschafts Simulator 15 .lnk
2015-05-02 14:20 - 2014-10-30 15:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Landwirtschafts Simulator 2015
2015-05-02 14:20 - 2014-10-03 15:13 - 00203054 _____ () C:\WINDOWS\DirectX.log
2015-05-02 04:39 - 2014-08-14 14:02 - 00000000 ____D () C:\ProgramData\MFAData
2015-05-02 04:34 - 2014-12-20 13:55 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-05-02 02:54 - 2014-08-14 13:44 - 00000000 ____D () C:\Users\Adrian
2015-05-01 22:46 - 2013-08-22 17:36 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2015-05-01 22:37 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-05-01 22:31 - 2014-11-29 15:55 - 00000000 ____D () C:\Program Files\KMSpico
2015-05-01 18:33 - 2014-12-24 16:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2015-05-01 14:27 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-04-30 22:20 - 2014-08-14 13:59 - 00002195 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2015-04-29 16:54 - 2014-08-14 13:49 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-04-29 16:54 - 2013-08-23 01:24 - 00764340 _____ () C:\WINDOWS\system32\perfh007.dat
2015-04-29 16:54 - 2013-08-23 01:24 - 00159160 _____ () C:\WINDOWS\system32\perfc007.dat
2015-04-28 19:16 - 2015-01-05 19:54 - 00000000 ____D () C:\Program Files (x86)\Brother
2015-04-28 19:16 - 2014-09-26 23:17 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2015-04-28 19:14 - 2015-01-23 22:22 - 00000000 ____D () C:\Program Files (x86)\Overwolf
2015-04-28 19:10 - 2014-08-14 13:40 - 00000000 ____D () C:\WINDOWS\Minidump
2015-04-27 22:02 - 2013-08-22 17:36 - 00000000 __SHD () C:\Program Files\Windows Sidebar
2015-04-27 22:02 - 2013-08-22 17:36 - 00000000 ___SD () C:\Program Files (x86)\Windows Sidebar
2015-04-26 16:27 - 2014-10-14 15:03 - 00181248 ___SH () C:\Users\Adrian\Desktop\Thumbs.db
2015-04-24 13:56 - 2015-02-05 21:45 - 00001068 _____ () C:\Users\Adrian\Desktop\Dropbox.lnk
2015-04-24 13:56 - 2015-02-05 21:43 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-19 20:20 - 2014-10-13 20:24 - 00000000 ____D () C:\Program Files\OBS
2015-04-19 20:20 - 2014-10-13 20:24 - 00000000 ____D () C:\Program Files (x86)\OBS
2015-04-18 10:28 - 2015-01-31 20:28 - 00000000 ____D () C:\ProgramData\Oracle
2015-04-18 10:26 - 2015-01-31 20:29 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-04-18 10:26 - 2015-01-31 20:28 - 00000000 ____D () C:\Program Files (x86)\Java
2015-04-17 14:34 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-04-17 14:31 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppCompat
2015-04-16 22:13 - 2015-03-16 18:01 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-04-16 22:12 - 2014-09-30 20:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-04-16 22:11 - 2014-12-17 20:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-04-16 17:03 - 2013-08-22 17:20 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-04-16 16:58 - 2013-08-22 15:25 - 00000167 _____ () C:\WINDOWS\win.ini
2015-04-16 16:51 - 2014-08-16 13:40 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-16 16:45 - 2014-08-16 13:39 - 128913832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-15 20:35 - 2014-12-03 16:28 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2015-04-14 18:35 - 2014-09-13 23:59 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-04-14 01:24 - 2013-08-22 17:38 - 00792056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-04-14 01:24 - 2013-08-22 17:38 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-04-11 15:10 - 2015-01-02 19:40 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-04-11 00:58 - 2014-10-03 14:39 - 00230400 ___SH () C:\Users\Adrian\Downloads\Thumbs.db
2015-04-10 03:13 - 2015-03-19 19:41 - 00226680 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.exe
2015-04-10 03:04 - 2014-10-29 20:57 - 00214392 _____ () C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2015-04-10 02:35 - 2014-08-30 02:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-10 02:35 - 2014-08-30 02:40 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-04-10 02:35 - 2014-08-14 21:04 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-10 02:33 - 2014-08-30 02:41 - 00000000 ____D () C:\Users\Adrian\AppData\Roaming\Mozilla
2015-04-07 03:06 - 2014-10-30 01:24 - 00000000 ____D () C:\Users\Adrian\Desktop\LS15
Some content of TEMP:
====================
C:\Users\Adrian\AppData\Local\Temp\AMDCleanupUtility.exe
C:\Users\Adrian\AppData\Local\Temp\AutoRun.exe
C:\Users\Adrian\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Adrian\AppData\Local\Temp\avgnt.exe
C:\Users\Adrian\AppData\Local\Temp\AviraSetup1295757718.exe
C:\Users\Adrian\AppData\Local\Temp\AviraSetup338337093.exe
C:\Users\Adrian\AppData\Local\Temp\bdfilters.dll
C:\Users\Adrian\AppData\Local\Temp\bdsinet.dll
C:\Users\Adrian\AppData\Local\Temp\Cleanup.dll
C:\Users\Adrian\AppData\Local\Temp\devcon.exe
C:\Users\Adrian\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Adrian\AppData\Local\Temp\drm_dyndata_7400008.dll
C:\Users\Adrian\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqvn8o_.dll
C:\Users\Adrian\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Adrian\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Adrian\AppData\Local\Temp\eauninstall.exe
C:\Users\Adrian\AppData\Local\Temp\helpdesk.exe
C:\Users\Adrian\AppData\Local\Temp\inetupdate.exe
C:\Users\Adrian\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\Adrian\AppData\Local\Temp\KMSpico_setup.exe
C:\Users\Adrian\AppData\Local\Temp\libeay32.dll
C:\Users\Adrian\AppData\Local\Temp\LMkRstPt.exe
C:\Users\Adrian\AppData\Local\Temp\msvcm80.dll
C:\Users\Adrian\AppData\Local\Temp\msvcp80.dll
C:\Users\Adrian\AppData\Local\Temp\msvcr80.dll
C:\Users\Adrian\AppData\Local\Temp\msxml3.dll
C:\Users\Adrian\AppData\Local\Temp\msxml3a.dll
C:\Users\Adrian\AppData\Local\Temp\msxml3r.dll
C:\Users\Adrian\AppData\Local\Temp\Need for Speed Most Wanted_uninst.exe
C:\Users\Adrian\AppData\Local\Temp\on4u2.dll
C:\Users\Adrian\AppData\Local\Temp\ose00001.exe
C:\Users\Adrian\AppData\Local\Temp\Quarantine.exe
C:\Users\Adrian\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Adrian\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\Adrian\AppData\Local\Temp\Setup.exe
C:\Users\Adrian\AppData\Local\Temp\sonarinst.exe
C:\Users\Adrian\AppData\Local\Temp\SpotifyUninstall.exe
C:\Users\Adrian\AppData\Local\Temp\sqlite3.dll
C:\Users\Adrian\AppData\Local\Temp\ssleay32.dll
C:\Users\Adrian\AppData\Local\Temp\VirusKillerOEM.exe
C:\Users\Adrian\AppData\Local\Temp\_is8FC4.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-30 11:58
==================== End Of Log ============================
--- --- ---
--- --- ---