Ok, habe alles durchgeführt. Anbei die Logs:
mbam: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 30.03.2014
Suchlauf-Zeit: 14:43:00
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.0.1000
Malware Datenbank: v2014.03.04.09
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7
CPU: x64
Dateisystem: NTFS
Benutzer: Junic
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 302671
Verstrichene Zeit: 5 Min, 32 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe, 2176, Löschen bei Neustart, [f40ce61a758b6d93aca1d9931ee2768a]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 30
PUP.Optional.Wajam.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WajamUpdater, In Quarantäne, [f40ce61a758b6d93aca1d9931ee2768a],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, In Quarantäne, [12ee11ef35cbde22ca12de96669cff01],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{1FAEE6D5-34F4-42AA-8025-3FD8F3EC4634}, In Quarantäne, [12ee11ef35cbde22ca12de96669cff01],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [6b9509f7a8586e9222bbc2b2fa082cd4],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}, In Quarantäne, [6b9509f7a8586e9222bbc2b2fa082cd4],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5D64294B-1341-4FE7-B6D8-7C36828D4DD5}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{095BFD3C-4602-4FE1-96F1-AEFAFBFD067D}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamBHO.1, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamBHO, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamBHO, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamBHO.1, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1814091315-1599528926-1494768749-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1814091315-1599528926-1494768749-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C}, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamDownloader.1, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\wajam.WajamDownloader, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamDownloader, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\wajam.WajamDownloader.1, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\CLASSES\APPID\priam_bho.DLL, In Quarantäne, [a957817f34ccd62a2802bfef689be31d],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\priam_bho.DLL, In Quarantäne, [18e8936d7d83926e2a00723c867d758b],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\jpmbfleldcgkldadpdinhjjopdfpjfjp, In Quarantäne, [778950b0fa06d62a97cff697e919b24e],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WAJAM, In Quarantäne, [9d6301ff0df343bd26072a8423e021df],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1814091315-1599528926-1494768749-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [21df669a956be11f715d1b8f29dad927],
PUP.Optional.Wajam.A, HKU\S-1-5-21-1814091315-1599528926-1494768749-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM, In Quarantäne, [000024dc9e6289778f9da20c689b7b85],
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Wajam, In Quarantäne, [2fd124dcc73957a9e2780086d131966a],
Registrierungswerte: 3
PUP.Optional.Wajam.A, HKLM\SOFTWARE\WOW6432NODE\WAJAM|red, 3, In Quarantäne, [9d6301ff0df343bd26072a8423e021df]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1814091315-1599528926-1494768749-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0T1I1H1M1GtG0LtF0N, In Quarantäne, [21df669a956be11f715d1b8f29dad927]
PUP.Optional.Wajam.A, HKU\S-1-5-21-1814091315-1599528926-1494768749-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\WAJAM|affiliate_id, 6447, In Quarantäne, [000024dc9e6289778f9da20c689b7b85]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 10
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam, Löschen bei Neustart, [2fd124dcc73957a9e2780086d131966a],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\IE, In Quarantäne, [2fd124dcc73957a9e2780086d131966a],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Updater, Löschen bei Neustart, [2fd124dcc73957a9e2780086d131966a],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam, In Quarantäne, [46ba738d827e3dc3d8382365ae5426da],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\html, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\js, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Wajam, In Quarantäne, [f10fd030ab55f10fb297aae0b1517b85],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Wajam\Chrome, In Quarantäne, [f10fd030ab55f10fb297aae0b1517b85],
Dateien: 16
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe, Löschen bei Neustart, [f40ce61a758b6d93aca1d9931ee2768a],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\IE\priam_bho.dll, In Quarantäne, [7888df213cc4916ff0ed87ece121de22],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\uninstall.exe, In Quarantäne, [2fd124dcc73957a9e2780086d131966a],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\IE\favicon.ico, In Quarantäne, [2fd124dcc73957a9e2780086d131966a],
PUP.Optional.Wajam.A, C:\Program Files (x86)\Wajam\Updater\wajamLogo.bmp, In Quarantäne, [2fd124dcc73957a9e2780086d131966a],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam\uninstall.lnk, In Quarantäne, [46ba738d827e3dc3d8382365ae5426da],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\manifest.json, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\priam_icon_128x128.png, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\priam_icon_48x48.png, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\html\background.html, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\js\background.js, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\js\browserLoad.js, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\js\priam.js, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\js\priam_background.js, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.34_0\js\priam_chrome.js, In Quarantäne, [55ab39c7ce327e82e31f52370bf75fa1],
PUP.Optional.Wajam.A, C:\Users\Junic\AppData\Local\Wajam\Chrome\wajam.crx, In Quarantäne, [f10fd030ab55f10fb297aae0b1517b85],
Physische Sektoren: 0
(No malicious items detected)
(end) adwcleaner: Code:
# AdwCleaner v3.022 - Bericht erstellt am 30/03/2014 um 14:56:41
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium (64 bits)
# Benutzername : Junic - JUNIC-PC
# Gestartet von : C:\Users\Junic\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage
Datei Gelöscht : C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.wajam.com_0.localstorage-journal
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasmancs
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\WajamUpdater
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16476
-\\ Mozilla Firefox v
[ Datei : C:\Users\Junic\AppData\Roaming\Mozilla\Firefox\Profiles\8o40jok2.default\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [1908 octets] - [30/03/2014 14:54:59]
AdwCleaner[S0].txt - [1733 octets] - [30/03/2014 14:56:41]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1793 octets] ########## junkware: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows 7 Home Premium x64
Ran by Junic on 30.03.2014 at 15:00:27,92
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 30.03.2014 at 15:07:33,93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014
Ran by Junic (administrator) on JUNIC-PC on 30-03-2014 15:08:21
Running from C:\Users\Junic\Desktop
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
() C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Gainward Co. Ltd.) C:\Program Files (x86)\EXPERTool\TBPanel.exe
(Spotify Ltd) C:\Users\Junic\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
(Razer USA Ltd) C:\Program Files (x86)\Razer\Imperator\RazerImperatorSysTray.exe
(Dropbox, Inc.) C:\Users\Junic\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CTHELPER.EXE
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe
(Samsung Electronics.) C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(E-MU Systems) C:\Program Files (x86)\Creative Professional\E-MU PatchMix DSP\EmuPMixDSP.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) c:\program files\windows defender\MpCmdRun.exe
(Google Inc.) C:\Users\Junic\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Junic\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Junic\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Junic\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Junic\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Junic\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Junic\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor)
HKLM-x32\...\Run: [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe [43608 2010-09-07] ()
HKLM-x32\...\Run: [Razer Imperator Driver] - C:\Program Files (x86)\Razer\Imperator\RazerImperatorSysTray.exe [979360 2012-02-09] (Razer USA Ltd)
HKLM-x32\...\Run: [AsioThk32Reg] - REGSVR32.EXE /S CTASIO.DLL
HKLM-x32\...\Run: [CTHelper] - C:\Windows\SysWOW64\CTHELPER.EXE [23040 2008-03-20] (Creative Technology Ltd)
HKLM-x32\...\Run: [CTxfiHlp] - C:\Windows\SysWOW64\CTXFIHLP.EXE [23552 2008-03-20] (Creative Technology Ltd)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-03-23] (AVAST Software)
HKU\S-1-5-21-1814091315-1599528926-1494768749-1000\...\Run: [TBPanel] - C:\Program Files (x86)\EXPERTool\TBPanel.exe [2045296 2012-05-24] (Gainward Co. Ltd.)
HKU\S-1-5-21-1814091315-1599528926-1494768749-1000\...\Run: [DAEMON Tools Lite] - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3672384 2012-04-11] (DT Soft Ltd)
HKU\S-1-5-21-1814091315-1599528926-1494768749-1000\...\Run: [Spotify Web Helper] - C:\Users\Junic\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171968 2014-02-13] (Spotify Ltd)
Startup: C:\Users\Junic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Junic\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Junic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Magician.lnk
ShortcutTarget: Samsung Magician.lnk -> C:\Program Files (x86)\Samsung SSD Magician\Samsung Magician.exe (Samsung Electronics.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x64514BF844D9CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Junic\AppData\Roaming\Mozilla\Firefox\Profiles\8o40jok2.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_77.dll ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.40.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Junic\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Junic\AppData\Local\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
Chrome:
=======
CHR HomePage:
CHR Plugin: (Shockwave Flash) - C:\Users\Junic\AppData\Local\Google\Chrome\Application\33.0.1750.154\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Junic\AppData\Local\Google\Chrome\Application\33.0.1750.154\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Junic\AppData\Local\Google\Chrome\Application\33.0.1750.154\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (Google Update) - C:\Users\Junic\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_287.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (SmallringFX MetalSliver Theme) - C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\amoaokkohdcekgomnddkdfocbifmiafo [2012-08-11]
CHR Extension: (AdBlock) - C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2012-08-11]
CHR Extension: (avast! Online Security) - C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-03-23]
CHR Extension: (Google Wallet) - C:\Users\Junic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-13]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-03-23]
==================== Services (Whitelisted) =================
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-10-12] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-10-12] (ASUSTeK Computer Inc.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-10-12] (ASUSTeK Computer Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-23] (AVAST Software)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-10-12] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2012-10-12] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-03-23] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-03-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-03-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-03-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-03-23] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [84816 2014-03-23] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208928 2014-03-23] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2012-08-11] (DT Soft Ltd)
S3 pfc; C:\Windows\SysWOW64\drivers\pfc.sys [10368 2004-04-01] (Padus, Inc.)
R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2012-05-14] (Realtek Semiconductor Corporation )
R3 synusb64; C:\Windows\System32\DRIVERS\synusb64.sys [30352 2010-09-17] (Steinberg Media Technologies GmbH)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 COMMONFX.DLL; \SystemRoot\System32\COMMONFX.DLL [X]
S3 CTAUDFX.DLL; \SystemRoot\System32\CTAUDFX.DLL [X]
S3 CTEAPSFX.DLL; \SystemRoot\System32\CTEAPSFX.DLL [X]
S3 CTEDSPFX.DLL; \SystemRoot\System32\CTEDSPFX.DLL [X]
S3 CTEDSPIO.DLL; \SystemRoot\System32\CTEDSPIO.DLL [X]
S3 CTEDSPSY.DLL; \SystemRoot\System32\CTEDSPSY.DLL [X]
S3 CTSBLFX.DLL; \SystemRoot\System32\CTSBLFX.DLL [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-30 15:08 - 2014-03-30 15:08 - 00014570 _____ () C:\Users\Junic\Desktop\FRST.txt
2014-03-30 15:07 - 2014-03-30 15:07 - 00000625 _____ () C:\Users\Junic\Desktop\JRT.txt
2014-03-30 15:00 - 2014-03-30 15:00 - 00000000 ____D () C:\Windows\ERUNT
2014-03-30 14:58 - 2014-03-30 14:58 - 01038974 _____ (Thisisu) C:\Users\Junic\Desktop\JRT.exe
2014-03-30 14:57 - 2014-03-30 14:57 - 00001873 _____ () C:\Users\Junic\Desktop\AdwCleaner[S0].txt
2014-03-30 14:54 - 2014-03-30 14:56 - 00000000 ____D () C:\AdwCleaner
2014-03-30 14:53 - 2014-03-30 14:53 - 01950720 _____ () C:\Users\Junic\Desktop\adwcleaner.exe
2014-03-30 14:52 - 2014-03-30 14:52 - 00010459 _____ () C:\Users\Junic\Desktop\mbam.txt
2014-03-30 14:33 - 2014-03-30 14:45 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-30 14:29 - 2014-03-30 14:29 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-30 14:29 - 2014-03-30 14:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 14:29 - 2014-03-30 14:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-30 14:29 - 2014-03-05 09:26 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-30 14:29 - 2014-03-05 09:26 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-30 14:29 - 2014-03-05 09:26 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-30 14:28 - 2014-03-30 14:28 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Junic\Desktop\mbam-setup-2.0.0.1000.exe
2014-03-30 14:27 - 2014-03-30 14:27 - 02157056 _____ (Farbar) C:\Users\Junic\Desktop\FRST64.exe
2014-03-29 16:59 - 2014-03-29 16:59 - 03598099 _____ () C:\Users\Junic\Desktop\SC2_1920.zip
2014-03-29 16:35 - 2014-03-29 16:35 - 00022477 _____ () C:\ComboFix.txt
2014-03-29 16:24 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-03-29 16:24 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-03-29 16:24 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-03-29 16:24 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-03-29 16:24 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-03-29 16:24 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-03-29 16:24 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-03-29 16:24 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-03-29 16:20 - 2014-03-29 16:35 - 00000000 ____D () C:\Qoobox
2014-03-29 16:20 - 2014-03-29 16:34 - 00000000 ____D () C:\Windows\erdnt
2014-03-23 14:19 - 2014-03-30 14:57 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-23 14:19 - 2014-03-23 14:19 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-03-23 14:19 - 2014-03-23 14:19 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-03-23 14:19 - 2014-03-23 14:19 - 00000000 ____D () C:\Users\Junic\AppData\Roaming\AVAST Software
2014-03-23 14:18 - 2014-03-23 14:18 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-03-23 14:18 - 2014-03-23 14:18 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-22 20:22 - 2014-03-30 15:08 - 00000000 ____D () C:\FRST
2014-03-22 18:01 - 2014-03-22 18:01 - 01699924 _____ () C:\Users\Junic\Desktop\sc2.rar
2014-03-12 23:09 - 2014-03-12 23:12 - 00000059 _____ () C:\Users\Junic\Desktop\CPLAY.txt
==================== One Month Modified Files and Folders =======
2014-03-30 15:08 - 2014-03-30 15:08 - 00014570 _____ () C:\Users\Junic\Desktop\FRST.txt
2014-03-30 15:08 - 2014-03-22 20:22 - 00000000 ____D () C:\FRST
2014-03-30 15:07 - 2014-03-30 15:07 - 00000625 _____ () C:\Users\Junic\Desktop\JRT.txt
2014-03-30 15:04 - 2009-07-14 06:45 - 00014800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-30 15:04 - 2009-07-14 06:45 - 00014800 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-30 15:03 - 2009-07-14 19:58 - 00657438 _____ () C:\Windows\system32\perfh007.dat
2014-03-30 15:03 - 2009-07-14 19:58 - 00130810 _____ () C:\Windows\system32\perfc007.dat
2014-03-30 15:03 - 2009-07-14 07:13 - 01507170 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-30 15:00 - 2014-03-30 15:00 - 00000000 ____D () C:\Windows\ERUNT
2014-03-30 15:00 - 2008-01-01 01:16 - 01892515 _____ () C:\Windows\WindowsUpdate.log
2014-03-30 14:58 - 2014-03-30 14:58 - 01038974 _____ (Thisisu) C:\Users\Junic\Desktop\JRT.exe
2014-03-30 14:58 - 2012-08-13 17:21 - 00000000 ____D () C:\Users\Junic\AppData\Roaming\TS3Client
2014-03-30 14:57 - 2014-03-30 14:57 - 00001873 _____ () C:\Users\Junic\Desktop\AdwCleaner[S0].txt
2014-03-30 14:57 - 2014-03-23 14:19 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-30 14:57 - 2012-12-19 17:54 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-03-30 14:57 - 2012-09-15 17:39 - 00135994 _____ () C:\Windows\PFRO.log
2014-03-30 14:57 - 2012-08-28 15:23 - 00077719 _____ () C:\Windows\setupact.log
2014-03-30 14:57 - 2012-08-16 19:23 - 00000000 ____D () C:\Users\Junic\AppData\Roaming\Dropbox
2014-03-30 14:57 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-30 14:56 - 2014-03-30 14:54 - 00000000 ____D () C:\AdwCleaner
2014-03-30 14:53 - 2014-03-30 14:53 - 01950720 _____ () C:\Users\Junic\Desktop\adwcleaner.exe
2014-03-30 14:52 - 2014-03-30 14:52 - 00010459 _____ () C:\Users\Junic\Desktop\mbam.txt
2014-03-30 14:45 - 2014-03-30 14:33 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-30 14:44 - 2012-08-13 17:06 - 00000000 ____D () C:\Windows\PCHEALTH
2014-03-30 14:42 - 2013-07-14 11:34 - 00000000 ____D () C:\Users\Junic\AppData\Local\Battle.net
2014-03-30 14:29 - 2014-03-30 14:29 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-30 14:29 - 2014-03-30 14:29 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-30 14:29 - 2014-03-30 14:29 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-03-30 14:28 - 2014-03-30 14:28 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Junic\Desktop\mbam-setup-2.0.0.1000.exe
2014-03-30 14:27 - 2014-03-30 14:27 - 02157056 _____ (Farbar) C:\Users\Junic\Desktop\FRST64.exe
2014-03-30 14:20 - 2012-10-13 13:32 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-30 14:09 - 2008-01-01 02:04 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1814091315-1599528926-1494768749-1000UA.job
2014-03-29 16:59 - 2014-03-29 16:59 - 03598099 _____ () C:\Users\Junic\Desktop\SC2_1920.zip
2014-03-29 16:35 - 2014-03-29 16:35 - 00022477 _____ () C:\ComboFix.txt
2014-03-29 16:35 - 2014-03-29 16:20 - 00000000 ____D () C:\Qoobox
2014-03-29 16:35 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-03-29 16:34 - 2014-03-29 16:20 - 00000000 ____D () C:\Windows\erdnt
2014-03-29 16:34 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-03-23 22:51 - 2012-08-20 20:44 - 00000000 ____D () C:\Users\Junic\Desktop\z
2014-03-23 14:19 - 2014-03-23 14:19 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-03-23 14:19 - 2014-03-23 14:19 - 00208928 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00084816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-03-23 14:19 - 2014-03-23 14:19 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-03-23 14:19 - 2014-03-23 14:19 - 00000000 ____D () C:\Users\Junic\AppData\Roaming\AVAST Software
2014-03-23 14:18 - 2014-03-23 14:18 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-03-23 14:18 - 2014-03-23 14:18 - 00000000 ____D () C:\Program Files\AVAST Software
2014-03-23 13:55 - 2014-02-01 15:42 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-03-22 18:01 - 2014-03-22 18:01 - 01699924 _____ () C:\Users\Junic\Desktop\sc2.rar
2014-03-22 16:18 - 2013-07-14 11:34 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-03-22 11:09 - 2008-01-01 02:04 - 00001068 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1814091315-1599528926-1494768749-1000Core.job
2014-03-15 04:01 - 2012-08-13 17:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-03-14 22:25 - 2013-10-16 19:26 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-03-14 20:50 - 2012-08-13 17:21 - 00000000 ____D () C:\Program Files\TeamSpeak 3 Client
2014-03-12 23:12 - 2014-03-12 23:09 - 00000059 _____ () C:\Users\Junic\Desktop\CPLAY.txt
2014-03-12 21:30 - 2013-07-14 11:10 - 00000000 ____D () C:\Users\Junic\AppData\Local\Adobe
2014-03-12 21:30 - 2012-10-13 13:32 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-03-12 21:30 - 2012-09-15 14:16 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-03-12 21:30 - 2012-09-15 14:16 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-03-06 19:58 - 2013-04-11 11:50 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-03-06 19:58 - 2012-08-13 17:23 - 00000000 ____D () C:\ProgramData\Skype
2014-03-05 09:26 - 2014-03-30 14:29 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-03-30 14:29 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-03-30 14:29 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
Some content of TEMP:
====================
C:\Users\Junic\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-30 13:49
==================== End Of Log ============================ --- --- --- |