So ich habe den Oxy Virus und Pilefile Reminder auf meinen PC bekommen und kann sie nichmehr entfernen.
FRST-File packe ich schoneinmal hier rein.
Code:
Alles auswählen Aufklappen ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Panda (administrator) on USER-TOSH on 01-04-2014 16:57:01
Running from C:\Users\Panda\Desktop
Microsoft Windows 7 Home Basic Service Pack 1 (X86) OS Language: English(US)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Broadcom Corporation.) C:\Windows\system32\BtwRSupportService.exe
() C:\ProgramData\DatacardService\HWDeviceService.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(LogMeIn, Inc.) C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) c:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
() C:\Windows\system32\PnkBstrA.exe
(TOSHIBA Corporation) C:\Windows\system32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
(LogMeIn Inc.) C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
(Microsoft Corporation) c:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Valve Corporation) D:\Steam\Steam.exe
(Spotify Ltd) C:\Users\Panda\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
(TOSHIBA CORPORATION) C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1697064 2010-03-10] (Synaptics Incorporated)
HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [611672 2010-02-05] (TOSHIBA Corporation)
HKLM\...\Run: [StartCCC] - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-03-15] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [SmartAudio] - C:\Program Files\CONEXANT\SAII\SAIICpl.exe [307768 2009-11-19] ()
HKLM\...\Run: [cAudioFilterAgent] - C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent.exe [496184 2010-03-22] (Conexant Systems, Inc.)
HKLM\...\Run: [TPwrMain] - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [480608 2009-11-05] (TOSHIBA Corporation)
HKLM\...\Run: [HSON] - C:\Program Files\TOSHIBA\TBS\HSON.exe [55160 2009-03-09] (TOSHIBA Corporation)
HKLM\...\Run: [SmoothView] - C:\Program Files\Toshiba\SmoothView\SmoothView.exe [521528 2009-08-13] (TOSHIBA Corporation)
HKLM\...\Run: [00TCrdMain] - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [742712 2010-03-03] (TOSHIBA Corporation)
HKLM\...\Run: [TWebCamera] - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2454840 2010-02-23] (TOSHIBA CORPORATION.)
HKLM\...\Run: [TosWaitSrv] - C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [611672 2010-02-23] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] - C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [22840 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [MSC] - C:\Program Files\Microsoft Security Client\msseces.exe [948440 2013-10-23] (Microsoft Corporation)
HKLM\...\Run: [SunJavaUpdateSched] - "C:\Program Files\Java\jre7\bin\jusched.exe"
HKLM\...\Run: [mobilegeni daemon] - C:\Program Files\Mobogenie\DaemonProcess.exe
HKLM\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe [3814736 2014-02-26] (LogMeIn Inc.)
HKLM\...\Run: [EvtMgr6] - C:\Program Files\Logitech\SetPointP\SetPoint.exe [2296600 2013-07-31] (Logitech, Inc.)
HKLM\...\Run: [Launch LCore] - C:\Program Files\Logitech Gaming Software\LCore.exe [6215448 2014-02-28] (Logitech Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\.DEFAULT\...\Run: [TOSHIBA Online Product Information] - C:\Program Files\TOSHIBA\TOSHIBA Online Product Information\topi.exe [4581280 2010-03-03] (TOSHIBA)
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\Run: [Steam] - D:\Steam\steam.exe [1821888 2014-02-25] (Valve Corporation)
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\Run: [Spotify Web Helper] - C:\Users\Panda\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-01-19] (Spotify Ltd)
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\Run: [NextLive] - C:\Windows\system32\rundll32.exe "C:\Users\Panda\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\RunOnce: [Credential® Backup® and Restore® Wizard®] - C:\Users\Panda\AppData\Roaming\Adobe\credwiz.exe [18432 2014-02-04] ()
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\MountPoints2: {01d2b440-2e35-11e3-8473-00266c74c646} - G:\LGAutoRun.exe
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\MountPoints2: {55377635-f393-11e2-a3bb-00266c74c646} - G:\AutoRun.exe
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\MountPoints2: {55377637-f393-11e2-a3bb-00266c74c646} - G:\AutoRun.exe
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\MountPoints2: {5537763e-f393-11e2-a3bb-00266c74c646} - G:\AutoRun.exe
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\MountPoints2: {55377642-f393-11e2-a3bb-00266c74c646} - G:\AutoRun.exe
HKU\S-1-5-21-4003422770-1054552077-3116443824-1000\...\MountPoints2: {ee921dec-e9c8-11e2-b0d4-00266c74c646} - F:\autorun.exe
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Free\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Panda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Produktregistrierung.lnk
ShortcutTarget: Logitech . Produktregistrierung.lnk -> C:\Program Files\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://msn.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.awesomehp.com/?type=hp&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.awesomehp.com/?type=hp&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.awesomehp.com/web/?type=ds&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.awesomehp.com/?type=sc&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351&q={searchTerms}
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351&q={searchTerms}
SearchScopes: HKCU - DefaultScope {1156D21F-3C7B-4729-8645-B75006C33220} URL =
SearchScopes: HKCU - {1156D21F-3C7B-4729-8645-B75006C33220} URL =
SearchScopes: HKCU - {11A20CEA-EA27-416B-ABA0-D195C870559E} URL = hxxp://www.amazon.co.uk/gp/search?ie=UTF8&keywords={searchTerms}&tag=tochibauk-win7-ie-search-21&index=blended&linkCode=ur2
SearchScopes: HKCU - {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.awesomehp.com/web/?type=ds&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351&q={searchTerms}
SearchScopes: HKCU - {744675FD-C406-4B26-8494-1F62EA899393} URL = hxxp://rover.ebay.com/rover/1/710-71511-9400-6/4?satitle={searchTerms}
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Skype add-on for Internet Explorer - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: TOSHIBA Media Controller Plug-in - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0051-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_51-windows-i586.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Chrome:
=======
CHR HomePage: hxxp://www.awesomehp.com/?type=hp&ts=1392907002&from=tugs&uid=ST9250315AS_6VC5P351XXXX6VC5P351
CHR Extension: (YTAddRemoval) - C:\Users\Panda\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjbhapkioddmfbdoagpkjfgkeamlkdla [2014-02-13]
CHR Extension: (AdBlock) - C:\Users\Panda\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-01-13]
CHR Extension: (Google Wallet) - C:\Users\Panda\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-21]
CHR HKLM\...\Chrome\Extension: [pelmeidfhdlhlbjimpabfcbnnojbboma] - C:\Users\Panda\AppData\Local\Google\Chrome\User Data\Default\Extensions\newtabv2.crx [2014-02-20]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
========================== Services (Whitelisted) =================
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [1680088 2013-10-28] (Broadcom Corporation.)
S3 BEService; C:\Program Files\Common Files\BattlEye\BEService.exe [49152 2014-01-22] ()
R2 cfWiMAXService; C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe [185712 2010-01-28] (TOSHIBA CORPORATION)
R2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [46448 2009-03-10] (TOSHIBA CORPORATION)
R2 Hamachi2Svc; C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [1678672 2014-02-26] (LogMeIn Inc.)
R2 HWDeviceService.exe; C:\ProgramData\DatacardService\HWDeviceService.exe [271712 2011-03-14] ()
R2 LMIGuardianSvc; C:\Program Files\LogMeIn Hamachi\LMIGuardianSvc.exe [375056 2014-02-26] (LogMeIn, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-08-16] ()
S3 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [124368 2010-05-11] (Toshiba Europe GmbH)
S3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51512 2009-10-06] (TOSHIBA Corporation)
R2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [189808 2010-03-17] (TOSHIBA Corporation)
R3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2010-02-05] (TOSHIBA Corporation)
R3 TPCHSrv; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [685424 2010-02-23] (TOSHIBA Corporation)
S2 0158231370818925mcinstcleanup; C:\Users\Panda\AppData\Local\Temp\015823~1.EXE -cleanup -nolog [X]
==================== Drivers (Whitelisted) ====================
R3 amdkmdag; C:\Windows\System32\DRIVERS\atipmdag.sys [5340160 2010-03-15] (ATI Technologies Inc.)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag.sys [23040 2012-07-03] (LG Electronics Inc.)
S3 AndNetDiag2; C:\Windows\System32\DRIVERS\lgandnetdiag2.sys [23040 2012-07-03] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem.sys [27776 2012-07-03] (LG Electronics Inc.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [175320 2013-10-28] (Broadcom Corporation.)
S3 btwampfl; C:\Windows\System32\DRIVERS\btwampfl.sys [144600 2013-10-28] (Broadcom Corporation.)
R3 CnxtHdmiAudService; C:\Windows\System32\drivers\CHDMI32.sys [516152 2010-03-05] (Conexant Systems Inc.)
R3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [90368 2011-02-25] (Huawei Technologies Co., Ltd.)
S3 huawei_cdcecm; C:\Windows\System32\DRIVERS\ew_jucdcecm.sys [64384 2011-01-30] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26624 2011-01-30] (Huawei Technologies Co., Ltd.)
R3 LGBusEnum; C:\Windows\System32\drivers\LGBusEnum.sys [19720 2009-11-24] (Logitech Inc.)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [39960 2013-05-30] (Logitech Inc.)
R3 LGVirHid; C:\Windows\System32\drivers\LGVirHid.sys [14856 2009-11-24] (Logitech Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
R2 TVALZFL; C:\Windows\System32\DRIVERS\TVALZFL.sys [12920 2009-06-19] (TOSHIBA Corporation)
U5 ew_hwusbdev; C:\Windows\System32\Drivers\ew_hwusbdev.sys [102784 2010-07-27] (Huawei Technologies Co., Ltd.)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-01 00:20 - 2014-04-01 16:57 - 00018201 _____ () C:\Users\Panda\Desktop\FRST.txt
2014-04-01 00:20 - 2014-04-01 16:57 - 00000000 ____D () C:\FRST
2014-04-01 00:19 - 2014-04-01 00:19 - 01145856 _____ (Farbar) C:\Users\Panda\Desktop\FRST.exe
2014-03-30 23:43 - 2014-03-30 23:43 - 00000000 ____D () C:\Users\Panda\AppData\Local\GCC
2014-03-30 00:44 - 2014-04-01 14:16 - 00000466 _____ () C:\Windows\Tasks\AmiUpdXp.job
2014-03-30 00:44 - 2014-03-30 00:44 - 00000000 ____D () C:\Users\Panda\AppData\Local\d4987079-28b4-4b33-f39e-d6d27588ab50
2014-03-30 00:43 - 2014-03-30 00:43 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-30 00:42 - 2014-03-30 00:43 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\Oxy
2014-03-30 00:41 - 2014-03-30 00:41 - 05456976 _____ () C:\Users\Panda\Downloads\Goat_Simulator_Downloader.exe
2014-03-29 15:09 - 2014-03-29 15:09 - 00000000 ____D () C:\Users\Panda\Desktop\Rust Server v25.02.2014 by Zadcrix
2014-03-29 14:41 - 2014-03-29 15:03 - 465003052 _____ () C:\Users\Panda\Downloads\Rust Server v25.02.2014 by Zadcrix.rar
2014-03-27 17:23 - 2014-03-27 17:23 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\com.valve.FTP
2014-03-23 15:37 - 2014-03-23 15:42 - 00000340 _____ () C:\Windows\LkmdfCoInst.log
2014-03-23 15:36 - 2014-03-23 15:37 - 00000000 ____D () C:\Program Files\Logitech Gaming Software
2014-03-23 15:34 - 2014-03-23 15:35 - 52257024 _____ (Logitech Inc.) C:\Users\Panda\Downloads\LGS_8.52.15_x86_Logitech.exe
2014-03-23 15:23 - 2014-03-23 15:25 - 00000000 ____D () C:\ProgramData\Logishrd
2014-03-23 15:23 - 2014-03-23 15:23 - 00000000 ____D () C:\Program Files\Logitech
2014-03-23 15:14 - 2014-03-23 15:18 - 79732624 _____ (Logitech Inc.) C:\Users\Panda\Downloads\setpoint6.61.15_32.exe
2014-03-23 14:54 - 2014-03-23 14:58 - 119932208 _____ (Logitech Inc. ) C:\Users\Panda\Downloads\setpoint480_btw.exe
2014-03-23 14:51 - 2014-03-23 14:52 - 81855696 _____ (Logitech Inc.) C:\Users\Panda\Downloads\setpoint6.61.150_64.exe
2014-03-23 14:28 - 2014-03-23 15:24 - 00018800 _____ () C:\Windows\LDPINST.LOG
2014-03-22 18:58 - 2014-03-22 18:58 - 00000000 ____D () C:\Users\Panda\AppData\Local\Skype
2014-03-22 18:57 - 2014-03-22 18:57 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-17 23:48 - 2014-03-30 20:26 - 00000000 ____D () C:\Users\Panda\Desktop\bilder FB
2014-03-12 13:25 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-12 13:25 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-12 13:25 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-12 13:25 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-12 13:25 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-12 13:25 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-12 13:25 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-12 13:25 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-12 13:25 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-12 13:25 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-12 13:25 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-12 13:25 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-12 13:25 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-12 13:25 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-12 13:25 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-12 13:25 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-12 13:25 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-12 13:25 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-12 13:25 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-12 13:25 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-12 13:25 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-12 13:25 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-12 13:25 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-12 13:24 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-12 13:24 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
==================== One Month Modified Files and Folders =======
2014-04-01 16:58 - 2014-04-01 00:20 - 00018201 _____ () C:\Users\Panda\Desktop\FRST.txt
2014-04-01 16:57 - 2014-04-01 00:20 - 00000000 ____D () C:\FRST
2014-04-01 16:57 - 2013-12-30 06:16 - 00011812 _____ () C:\Windows\setupact.log
2014-04-01 16:40 - 2013-05-31 21:36 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-01 16:14 - 2013-12-13 00:36 - 00000000 ____D () C:\Users\Panda\Desktop\MSA
2014-04-01 16:07 - 2013-06-09 23:15 - 00001096 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-01 14:28 - 2009-07-14 06:34 - 00014320 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-01 14:28 - 2009-07-14 06:34 - 00014320 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-01 14:22 - 2010-06-09 17:03 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-01 14:19 - 2014-02-20 16:38 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\newnext.me
2014-04-01 14:17 - 2013-05-31 21:41 - 00000000 ____D () C:\Users\Panda\AppData\Local\LogMeIn Hamachi
2014-04-01 14:16 - 2014-03-30 00:44 - 00000466 _____ () C:\Windows\Tasks\AmiUpdXp.job
2014-04-01 14:16 - 2013-06-09 23:15 - 00001092 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-01 14:16 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-01 08:44 - 2013-05-31 17:08 - 01115543 _____ () C:\Windows\WindowsUpdate.log
2014-04-01 00:19 - 2014-04-01 00:19 - 01145856 _____ (Farbar) C:\Users\Panda\Desktop\FRST.exe
2014-03-31 21:54 - 2013-06-04 15:47 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\TS3Client
2014-03-30 23:43 - 2014-03-30 23:43 - 00000000 ____D () C:\Users\Panda\AppData\Local\GCC
2014-03-30 20:26 - 2014-03-17 23:48 - 00000000 ____D () C:\Users\Panda\Desktop\bilder FB
2014-03-30 20:26 - 2013-05-31 21:40 - 00000000 ____D () C:\Users\Panda\Desktop\Masin
2014-03-30 00:48 - 2014-02-20 16:38 - 00000000 ____D () C:\Users\Panda\AppData\Local\Mobogenie
2014-03-30 00:44 - 2014-03-30 00:44 - 00000000 ____D () C:\Users\Panda\AppData\Local\d4987079-28b4-4b33-f39e-d6d27588ab50
2014-03-30 00:44 - 2014-02-20 16:38 - 00000000 ____D () C:\Users\Panda\AppData\Local\cache
2014-03-30 00:43 - 2014-03-30 00:43 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Oxy
2014-03-30 00:43 - 2014-03-30 00:42 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\Oxy
2014-03-30 00:41 - 2014-03-30 00:41 - 05456976 _____ () C:\Users\Panda\Downloads\Goat_Simulator_Downloader.exe
2014-03-29 15:09 - 2014-03-29 15:09 - 00000000 ____D () C:\Users\Panda\Desktop\Rust Server v25.02.2014 by Zadcrix
2014-03-29 15:03 - 2014-03-29 14:41 - 465003052 _____ () C:\Users\Panda\Downloads\Rust Server v25.02.2014 by Zadcrix.rar
2014-03-28 18:04 - 2014-02-16 22:14 - 00000000 ____D () C:\Users\Panda\AppData\Local\DayZ
2014-03-27 17:23 - 2014-03-27 17:23 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\com.valve.FTP
2014-03-26 20:41 - 2013-06-03 19:34 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\Skype
2014-03-23 15:46 - 2013-05-31 21:37 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\Spotify
2014-03-23 15:42 - 2014-03-23 15:37 - 00000340 _____ () C:\Windows\LkmdfCoInst.log
2014-03-23 15:37 - 2014-03-23 15:36 - 00000000 ____D () C:\Program Files\Logitech Gaming Software
2014-03-23 15:37 - 2013-06-25 17:19 - 00016400 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2014-03-23 15:36 - 2013-06-25 17:18 - 00000000 ____D () C:\Users\Panda\AppData\Roaming\Logishrd
2014-03-23 15:35 - 2014-03-23 15:34 - 52257024 _____ (Logitech Inc.) C:\Users\Panda\Downloads\LGS_8.52.15_x86_Logitech.exe
2014-03-23 15:27 - 2013-06-25 17:19 - 00000000 ____D () C:\Users\Panda\AppData\Local\Logitech
2014-03-23 15:25 - 2014-03-23 15:23 - 00000000 ____D () C:\ProgramData\Logishrd
2014-03-23 15:25 - 2013-08-15 19:31 - 00000000 ____D () C:\Program Files\Common Files\LogiShrd
2014-03-23 15:24 - 2014-03-23 14:28 - 00018800 _____ () C:\Windows\LDPINST.LOG
2014-03-23 15:23 - 2014-03-23 15:23 - 00000000 ____D () C:\Program Files\Logitech
2014-03-23 15:22 - 2010-06-09 17:18 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-03-23 15:20 - 2014-01-16 04:21 - 00007900 _____ () C:\Windows\PFRO.log
2014-03-23 15:18 - 2014-03-23 15:14 - 79732624 _____ (Logitech Inc.) C:\Users\Panda\Downloads\setpoint6.61.15_32.exe
2014-03-23 14:58 - 2014-03-23 14:54 - 119932208 _____ (Logitech Inc. ) C:\Users\Panda\Downloads\setpoint480_btw.exe
2014-03-23 14:52 - 2014-03-23 14:51 - 81855696 _____ (Logitech Inc.) C:\Users\Panda\Downloads\setpoint6.61.150_64.exe
2014-03-22 18:58 - 2014-03-22 18:58 - 00000000 ____D () C:\Users\Panda\AppData\Local\Skype
2014-03-22 18:57 - 2014-03-22 18:57 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-03-22 18:57 - 2010-06-09 17:36 - 00000000 ___RD () C:\Program Files\Skype
2014-03-22 18:57 - 2010-06-09 17:36 - 00000000 ____D () C:\ProgramData\Skype
2014-03-19 21:20 - 2013-05-31 21:36 - 00000000 ____D () C:\Users\Panda\AppData\Local\Adobe
2014-03-19 21:19 - 2013-05-31 21:36 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-03-19 21:19 - 2013-05-31 21:36 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-03-19 17:15 - 2013-05-31 21:38 - 00000000 ____D () C:\Users\Panda\AppData\Local\Spotify
2014-03-19 04:03 - 2013-07-14 03:00 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-19 04:00 - 2013-06-02 22:40 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-03-13 17:41 - 2013-06-03 19:40 - 00000000 ____D () C:\Users\Panda\AppData\Local\TeamSpeak 3 Client
2014-03-13 04:19 - 2009-07-14 06:33 - 00486072 _____ () C:\Windows\system32\FNTCACHE.DAT
Some content of TEMP:
====================
C:\Users\Panda\AppData\Local\Temp\awesomium_setup.exe
C:\Users\Panda\AppData\Local\Temp\BackupSetup.exe
C:\Users\Panda\AppData\Local\Temp\htmlayout.dll
C:\Users\Panda\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Panda\AppData\Local\Temp\LMkRstPt.exe
C:\Users\Panda\AppData\Local\Temp\myuser.exe
C:\Users\Panda\AppData\Local\Temp\oi_{D6643009-5CB7-48B4-8EEC-B8DF1DFB6C4F}.exe
C:\Users\Panda\AppData\Local\Temp\OxyBrowserUpdater__3338_i491892894_il6465765.exe
C:\Users\Panda\AppData\Local\Temp\setup.exe
C:\Users\Panda\AppData\Local\Temp\SRLDetectionLibrary2604755237894843639.dll
C:\Users\Panda\AppData\Local\Temp\tmp168F.exe
C:\Users\Panda\AppData\Local\Temp\tmp2A04.exe
C:\Users\Panda\AppData\Local\Temp\tmp34A1.tmp.exe
C:\Users\Panda\AppData\Local\Temp\tmp43DD.exe
C:\Users\Panda\AppData\Local\Temp\tmp587A.exe
C:\Users\Panda\AppData\Local\Temp\tmp6CB9.exe
C:\Users\Panda\AppData\Local\Temp\tmp741.exe
C:\Users\Panda\AppData\Local\Temp\tmp8C6B.exe
C:\Users\Panda\AppData\Local\Temp\tmp9C17.exe
C:\Users\Panda\AppData\Local\Temp\tmpAB55.exe
C:\Users\Panda\AppData\Local\Temp\tmpD598.exe
C:\Users\Panda\AppData\Local\Temp\tmpDF82.exe
C:\Users\Panda\AppData\Local\Temp\tmpF7C5.exe
C:\Users\Panda\AppData\Local\Temp\UNINSTALL.EXE
C:\Users\Panda\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 02:54
==================== End Of Log ============================