Emmaline | 21.04.2014 10:24 | Sooo, hab die Audiodatei gelöscht und dann ging alles. Hier die ganzen Files Zitat:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 20.04.2014 07:18:43, SYSTEM, ACIDFREE-PC, Protection, Malware Protection, Starting,
Protection, 20.04.2014 07:18:43, SYSTEM, ACIDFREE-PC, Protection, Malware Protection, Started,
Protection, 20.04.2014 07:18:43, SYSTEM, ACIDFREE-PC, Protection, Malicious Website Protection, Starting,
Protection, 20.04.2014 07:19:17, SYSTEM, ACIDFREE-PC, Protection, Malicious Website Protection, Failed,
Error, 20.04.2014 07:19:17, SYSTEM, ACIDFREE-PC, Protection, MWAC::CreateList - Block List, 3221225473,
Detection, 20.04.2014 07:29:31, SYSTEM, ACIDFREE-PC, Protection, Malware Protection, File, PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Quarantine, [7eb7d3596f0c75c1c3e7283337ca2cd4]
Protection, 20.04.2014 07:29:31, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Error, 20.04.2014 07:29:31, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Update, 20.04.2014 07:46:06, SYSTEM, ACIDFREE-PC, Scheduler, Malware Database, 2014.4.19.9, 2014.4.20.2,
Protection, 20.04.2014 07:46:08, SYSTEM, ACIDFREE-PC, Protection, Refresh, Starting,
Protection, 20.04.2014 07:46:21, SYSTEM, ACIDFREE-PC, Protection, Refresh, Success,
Detection, 20.04.2014 07:49:00, Acidfree, ACIDFREE-PC, Protection, Malware Protection, File, PUP.Optional.InstallCore.A, C:\Users\Acidfree\AppData\Local\Temp\nsg2A15.tmp, Quarantine, [7d15012b67147db981ba234960a13bc5]
Detection, 20.04.2014 08:07:56, SYSTEM, ACIDFREE-PC, Protection, Malware Protection, File, PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Quarantine, [bdd52903ee8d84b2b6f52e2d6d943ac6]
Protection, 20.04.2014 08:07:56, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Error, 20.04.2014 08:07:56, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Detection, 20.04.2014 08:08:02, SYSTEM, ACIDFREE-PC, Protection, Malware Protection, File, PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Quarantine, [bdd52903ee8d84b2b6f52e2d6d943ac6]
Protection, 20.04.2014 08:08:02, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Error, 20.04.2014 08:08:02, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Detection, 20.04.2014 08:09:35, SYSTEM, ACIDFREE-PC, Protection, Malware Protection, File, PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Quarantine, [bdd52903ee8d84b2b6f52e2d6d943ac6]
Protection, 20.04.2014 08:09:35, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Error, 20.04.2014 08:09:35, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Detection, 20.04.2014 08:19:29, SYSTEM, ACIDFREE-PC, Protection, Malware Protection, File, PUP.Optional.WpManager, C:\ProgramData\WPM\wprotectmanager.exe, Quarantine, [bdd52903ee8d84b2b6f52e2d6d943ac6]
Protection, 20.04.2014 08:19:29, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Error, 20.04.2014 08:19:29, SYSTEM, ACIDFREE-PC, Protection, DeleteFile, 5, Failed, C:\ProgramData\WPM\wprotectmanager.exe,
Update, 20.04.2014 12:21:36, SYSTEM, ACIDFREE-PC, Scheduler, Malware Database, 2014.4.20.2, 2014.4.20.3,
Protection, 20.04.2014 12:21:37, SYSTEM, ACIDFREE-PC, Protection, Refresh, Starting,
Protection, 20.04.2014 12:21:49, SYSTEM, ACIDFREE-PC, Protection, Refresh, Success,
(end)
| Adw Cleaner hab ich ist aber zu groß. Liefere ich bei Bedarf. Zitat:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x64
Ran by Acidfree on 20.04.2014 at 13:49:51,00
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-4292617380-400896395-2015133285-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A4A37A65-E638-486B-831A-5511E241A09C}
~~~ Files
Successfully deleted: [File] "C:\Users\Acidfree\appdata\locallow\SkwConfig.bin"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted the following from C:\Users\Acidfree\AppData\Roaming\mozilla\firefox\profiles\bag98wu8.default\prefs.js
user_pref("CT2269050./9b+7e3x305.from_oldbar.enc", "JH4vQT87NjM/R0Y/fUk+QS52MH4iJCE1LDdHS1lXS0pIWFhOXjdiVzpTXkkySzo9PztQR1JibGJddXhtdmp8UXxxdGFKY1JVV1JoX2p6LSYsLCR+LzIuaTUqLXl
user_pref("CT2269050./9b+7ebx305.from_oldbar.enc", "JH4+OTFBMD0zRUA2Mn5KP0IvdzF7fSM1LDdWWUlITk9RUlxOTFVTW1RgWlo+aV5hTjdQOz1BVEtWdXVlbXNneW1tfFUhdXhlTmdSVFdrYm0tIiUuIGczKGokL3l
Emptied folder: C:\Users\Acidfree\AppData\Roaming\mozilla\firefox\profiles\bag98wu8.default\minidumps [457 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.04.2014 at 13:57:06,44
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
| FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 20-04-2014
Ran by Acidfree (administrator) on ACIDFREE-PC on 20-04-2014 14:07:43
Running from C:\Users\Acidfree\Desktop
Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Adobe Systems Incorporated) E:\Photoshop\PhotoshopElementsFileAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
( ) C:\Windows\system32\lxczcoms.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Spotify Ltd) C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
() C:\Program Files (x86)\FastMediaConverter\FastMediaConverterApp.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(Nullsoft, Inc.) D:\Winamp\winampa.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_182.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [WinampAgent] => D:\Winamp\winampa.exe [74752 2011-07-11] (Nullsoft, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-20] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [ICQ] => D:\ICQ7.5\ICQ.exe [124480 2011-08-01] (ICQ, LLC.)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Hoolapp Android] => /Minimized
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify Web Helper] => C:\Users\Acidfree\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1171000 2014-04-11] (Spotify Ltd)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [Spotify] => C:\Users\Acidfree\AppData\Roaming\Spotify\Spotify.exe [6087224 2014-04-11] (Spotify Ltd)
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\Run: [PrivacyDr] => C:\Program Files (x86)\Privacy Dr\PrivacyDr.exe
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {237ce8bd-cee5-11e0-b0cf-00242178af47} - J:\Startme.exe
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {2518b13b-372c-11e2-87e8-00242178af47} - G:\pushinst.exe
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {5738becf-f4ff-11e1-8895-806e6f6e6963} - explorer index_GB.html
HKU\S-1-5-21-4292617380-400896395-2015133285-1000\...\MountPoints2: {afbc22a3-b183-11e1-b4a9-00242178af47} - G:\Setup.exe
Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Startup: C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x449DEC206E54CC01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: ICQ Sparberater - {5A0D6E4B-B0DF-4148-8B1E-F7A430FF5E24} - C:\Program Files (x86)\icq\Internet Explorer\icq.dll (solute gmbh)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default
FF NewTab: chrome://quick_start/content/index.html
FF SearchEngineOrder.1: Google
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @java.com/DTPlugin,version=10.10.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.10.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.)
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\englische-ergebnisse.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\gmx-suche.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-26.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-27.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-28.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-29.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\icqplugin-30.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\lastminute.xml
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\searchplugins\webde-suche.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Evernote Web Clipper - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-19]
FF Extension: DivX Web Player - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\DivXWebPlayer@divx.com.xpi [2012-03-01]
FF Extension: GMX MailCheck - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar@gmx.net.xpi [2012-05-04]
FF Extension: Ask Toolbar - C:\Users\Acidfree\AppData\Roaming\Mozilla\Firefox\Profiles\bag98wu8.default\Extensions\toolbar_ORJ-V7C@apn.ask.com.xpi [2014-02-25]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2014-03-19]
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll No File
CHR Plugin: (Skype Toolbars) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\npSkypeChromePlugin.dll (Skype Technologies S.A.)
CHR Plugin: (registryAccess) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj\7.15.1.0_0\background/registryAccess.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.50.255) - C:\Windows\SysWOW64\npDeployJava1.dll No File
CHR Plugin: (Winamp Application Detector) - C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll (Nullsoft, Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File
CHR Plugin: (Unity Player) - C:\Users\Acidfree\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll No File
CHR Extension: (No Name) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaangaohdajkgeopjhpbnlpkehbhmbj [2012-09-02]
CHR Extension: (Skype Click to Call) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2011-08-19]
CHR Extension: (DivX Plus Web Player HTML5 <video>) - C:\Users\Acidfree\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-03-11]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-10-10]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor7.0; E:\Photoshop\PhotoshopElementsFileAgent.exe [169312 2008-09-16] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-20] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-03-26] (APN LLC.)
R2 lxcz_device; C:\Windows\system32\lxczcoms.exe [566192 2007-04-19] ( )
R2 lxcz_device; C:\Windows\SysWOW64\lxczcoms.exe [537520 2007-04-19] ( )
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
S2 vosr; C:\Users\Acidfree\AppData\Roaming\VOPackage\VOsrv.exe [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2013-12-17] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-04-20] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19032 2013-03-07] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [9584 2013-03-07] ()
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-20 14:07 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion
2014-04-20 13:57 - 2014-04-20 14:04 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt
2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe
2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT
2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt
2014-04-20 13:17 - 2014-04-20 13:24 - 00000000 ____D () C:\AdwCleaner
2014-04-20 13:17 - 2014-04-20 13:16 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe
2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt
2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP
2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp
2014-04-19 21:13 - 2014-04-20 13:37 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-19 21:13 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-19 21:13 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-19 21:13 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk
2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-18 12:01 - 2014-04-18 14:47 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash
2014-04-18 12:01 - 2014-04-18 12:03 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr
2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner
2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp
2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote
2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk
2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote
2014-04-18 10:02 - 2014-04-18 10:08 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt
2014-04-18 10:00 - 2014-04-20 14:07 - 02055680 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe
2014-04-18 10:00 - 2014-04-20 14:07 - 00017482 _____ () C:\Users\Acidfree\Desktop\FRST.txt
2014-04-18 10:00 - 2014-04-20 14:07 - 00000000 ____D () C:\FRST
2014-04-13 16:51 - 2014-04-20 13:48 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter
2014-04-13 16:51 - 2014-04-19 21:06 - 00000444 __RSH () C:\ProgramData\ntuser.pol
2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk
2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter
2014-04-09 07:24 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-09 07:24 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-09 07:24 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-09 07:24 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 07:24 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 07:24 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 07:24 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 07:24 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 07:24 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 07:24 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 07:24 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-09 07:24 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-09 07:24 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-09 07:24 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-09 07:24 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-09 07:24 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-09 07:24 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
==================== One Month Modified Files and Folders =======
2014-04-20 14:08 - 2014-04-18 10:00 - 00017482 _____ () C:\Users\Acidfree\Desktop\FRST.txt
2014-04-20 14:07 - 2014-04-20 14:07 - 00000000 ____D () C:\Users\Acidfree\Desktop\FRST-OlderVersion
2014-04-20 14:07 - 2014-04-18 10:00 - 02055680 _____ (Farbar) C:\Users\Acidfree\Desktop\FRST64.exe
2014-04-20 14:07 - 2014-04-18 10:00 - 00000000 ____D () C:\FRST
2014-04-20 14:06 - 2012-11-02 09:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-20 14:04 - 2014-04-20 13:57 - 00002052 _____ () C:\Users\Acidfree\Desktop\JRT.txt
2014-04-20 13:49 - 2014-04-20 13:49 - 01016261 _____ (Thisisu) C:\Users\Acidfree\Desktop\JRT.exe
2014-04-20 13:49 - 2014-04-20 13:49 - 00000000 ____D () C:\Windows\ERUNT
2014-04-20 13:48 - 2014-04-20 13:48 - 00123323 _____ () C:\Users\Acidfree\Desktop\AdwCleaner[S0].txt
2014-04-20 13:48 - 2014-04-13 16:51 - 00000000 ____D () C:\Program Files (x86)\FastMediaConverter
2014-04-20 13:48 - 2013-02-01 22:32 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Spotify
2014-04-20 13:47 - 2011-08-07 10:03 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\ICQ
2014-04-20 13:42 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-20 13:42 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-20 13:37 - 2014-04-19 21:13 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-20 13:36 - 2011-08-19 21:27 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-20 13:34 - 2011-09-16 05:04 - 00135787 _____ () C:\Windows\setupact.log
2014-04-20 13:34 - 2011-08-06 21:24 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-04-20 13:34 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-20 13:33 - 2011-08-06 20:48 - 01294945 _____ () C:\Windows\WindowsUpdate.log
2014-04-20 13:27 - 2011-08-19 21:27 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-20 13:24 - 2014-04-20 13:17 - 00000000 ____D () C:\AdwCleaner
2014-04-20 13:16 - 2014-04-20 13:17 - 01308369 _____ () C:\Users\Acidfree\Desktop\adwcleaner.exe
2014-04-20 13:03 - 2011-10-21 08:26 - 00319134 _____ () C:\Windows\PFRO.log
2014-04-20 13:00 - 2014-04-20 13:00 - 00003654 _____ () C:\Users\Acidfree\Desktop\mbam.txt
2014-04-19 22:47 - 2011-08-07 08:15 - 00000000 ____D () C:\Windows\System32\Tasks\Games
2014-04-19 22:40 - 2011-08-06 21:29 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-04-19 21:55 - 2014-04-19 21:55 - 423694260 _____ () C:\Windows\MEMORY.DMP
2014-04-19 21:55 - 2014-04-19 21:55 - 00298800 _____ () C:\Windows\Minidump\041914-17659-01.dmp
2014-04-19 21:55 - 2011-08-08 06:57 - 00000000 ____D () C:\Windows\Minidump
2014-04-19 21:13 - 2014-04-19 21:13 - 00001116 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-19 21:13 - 2014-04-19 21:13 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-19 21:13 - 2012-09-03 16:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-19 21:11 - 2011-08-06 21:34 - 00001152 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-19 21:11 - 2011-08-06 21:03 - 00001435 _____ () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-04-19 21:06 - 2014-04-13 16:51 - 00000444 __RSH () C:\ProgramData\ntuser.pol
2014-04-19 20:51 - 2014-04-19 20:51 - 00001278 _____ () C:\Users\Acidfree\Desktop\Revo Uninstaller.lnk
2014-04-19 20:51 - 2014-04-19 20:51 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-04-18 14:47 - 2014-04-18 12:01 - 00003368 _____ () C:\Windows\System32\Tasks\PrivacyDr_Splash
2014-04-18 12:03 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\Documents\PrivacyDr
2014-04-18 12:01 - 2014-04-18 12:01 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\HistoryCleaner
2014-04-18 11:58 - 2014-04-18 11:58 - 01097384 _____ (AnyProtect.com) C:\Users\Acidfree\AppData\Local\nsvD72C.tmp
2014-04-18 10:12 - 2011-08-06 21:03 - 00000000 ___RD () C:\Users\Acidfree\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-18 10:11 - 2014-04-18 10:11 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Evernote
2014-04-18 10:10 - 2014-04-18 10:10 - 00000932 _____ () C:\Users\Acidfree\Desktop\Evernote.lnk
2014-04-18 10:10 - 2014-04-18 10:10 - 00000000 ____D () C:\Program Files (x86)\Evernote
2014-04-18 10:08 - 2014-04-18 10:02 - 00027724 _____ () C:\Users\Acidfree\Desktop\Addition.txt
2014-04-14 17:29 - 2013-02-01 22:33 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Spotify
2014-04-14 04:21 - 2012-11-02 09:07 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-14 04:21 - 2012-10-03 13:28 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-14 04:21 - 2011-08-22 10:13 - 00000000 ____D () C:\Users\Acidfree\AppData\Local\Adobe
2014-04-14 04:21 - 2011-08-07 08:14 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-13 16:51 - 2014-04-13 16:51 - 00001146 _____ () C:\Users\Public\Desktop\Fast Media Converter.lnk
2014-04-13 16:51 - 2014-04-13 16:51 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\FastMediaConverter
2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-13 16:51 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-10 03:57 - 2013-05-23 19:02 - 00000000 ____D () C:\Windows\rescache
2014-04-10 03:02 - 2013-07-24 21:34 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-10 03:01 - 2011-12-12 08:37 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\ProgramData\AskPartnerNetwork
2014-04-06 17:19 - 2014-04-06 17:19 - 00000000 ____D () C:\Program Files (x86)\AskPartnerNetwork
2014-04-06 17:18 - 2014-04-06 17:18 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-06 17:17 - 2014-04-06 17:17 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-06 17:17 - 2012-09-13 16:16 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-06 17:17 - 2011-12-01 08:43 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-06 17:17 - 2011-12-01 08:43 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-06 17:17 - 2011-08-17 16:40 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-04 16:00 - 2009-07-14 19:58 - 00699432 _____ () C:\Windows\system32\perfh007.dat
2014-04-04 16:00 - 2009-07-14 19:58 - 00149572 _____ () C:\Windows\system32\perfc007.dat
2014-04-04 16:00 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-03 09:51 - 2014-04-19 21:13 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-19 21:13 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-19 21:13 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-31 18:50 - 2013-12-18 19:25 - 00000202 _____ () C:\Users\Acidfree\AppData\Roaming\WB.CFG
2014-03-31 03:16 - 2014-04-09 07:24 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 07:24 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 07:24 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-22 09:48 - 2011-10-20 17:38 - 00000000 ____D () C:\Users\Acidfree\AppData\Roaming\Winamp
Files to move or delete:
====================
C:\ProgramData\nud0repor.pad
Some content of TEMP:
====================
C:\Users\Acidfree\AppData\Local\Temp\APNSetup.exe
C:\Users\Acidfree\AppData\Local\Temp\avgnt.exe
C:\Users\Acidfree\AppData\Local\Temp\DWPUpgradeInstaller.exe
C:\Users\Acidfree\AppData\Local\Temp\installer.exe
C:\Users\Acidfree\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\Acidfree\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\Acidfree\AppData\Local\Temp\PrivacyDrSetup_S.exe
C:\Users\Acidfree\AppData\Local\Temp\Quarantine.exe
C:\Users\Acidfree\AppData\Local\Temp\setup.exe
C:\Users\Acidfree\AppData\Local\Temp\SkypeSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-09 06:09
==================== End Of Log ============================ --- --- ---
Ich mach dann mal die Anfangs Logs am Laptop. Den hab ich nicht so oft.
Liebe Grüße
Emmaline |