Noel Askatu | 22.04.2014 14:23 | So, hatte über das Wochenende kein Internet, Freitag hatte der Malwarebyte-Download nicht funktioniert (trotz klick auf Download keine Datei heruntergeladen, heute ging es aber).
mbam.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.04.2014
Suchlauf-Zeit: 12:42:43
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.04.22.03
Rootkit Datenbank: v2014.03.27.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: Noel
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 294248
Verstrichene Zeit: 15 Min, 23 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 2
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1450695444-39005048-1700824554-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [19e7c04001ff1be5babf3f411ee4659b],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1450695444-39005048-1700824554-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [50b0b54b0ff170905556a2f4bc47fd03],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1450695444-39005048-1700824554-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0C2Z1N1R0Q1D1J1C0Q1B, In Quarantäne, [50b0b54b0ff170905556a2f4bc47fd03]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 8
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\content, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\defaults, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\defaults\preferences, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\locale, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\locale\en-US, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\META-INF, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\skin, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
Dateien: 20
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\build.sh, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\chrome.manifest, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\config_build.sh, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\install.rdf, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\readme.txt, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\content\about.xul, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\content\firefoxOverlay.xul, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\content\options.xul, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\content\overlay.js, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\content\y2layers.jpg, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\defaults\preferences\y2layers.js, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\locale\en-US\about.dtd, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\locale\en-US\prefwindow.dtd, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\locale\en-US\y2layers.dtd, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\locale\en-US\y2layers.properties, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\META-INF\manifest.mf, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\META-INF\zigbert.rsa, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\META-INF\zigbert.sf, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\skin\overlay.css, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
PUP.Optional.Yontoo.A, C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\extensions\plugin@yontoo.com\skin\toolbar-button.png, In Quarantäne, [5fa1659bad539769d9766402a55d13ed],
Physische Sektoren: 0
(No malicious items detected)
(end) Adwcleaner: Code:
# AdwCleaner v3.200 - Bericht erstellt am 22/04/2014 um 12:54:28
# Aktualisiert 22/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Noel - NOEL-PC
# Gestartet von : C:\Users\Noel\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar
Ordner Gelöscht : C:\ProgramData\Partner
Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
Ordner Gelöscht : C:\Program Files (x86)\DVDVideoSoft
Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar
Ordner Gelöscht : C:\Program Files (x86)\Yontoo
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft
Ordner Gelöscht : C:\Users\Noel\AppData\Roaming\DVDVideoSoft
Ordner Gelöscht : C:\Users\Noel\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Users\Noel\AppData\Roaming\Yontoo
Ordner Gelöscht : C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\ICQToolbarData
Datei Gelöscht : C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\searchplugins\icqplugin.xml
Datei Gelöscht : C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\searchplugins\icqplugin-1.xml
Datei Gelöscht : C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\user.js
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\prefs.js ]
Zeile gelöscht : user_pref("extentions.y2layers.defaultEnableAppsList", "twittube,buzzdock,YontooNewOffers");
Zeile gelöscht : user_pref("extentions.y2layers.installId", "b55cb71c-2f73-41bb-b051-9c03ee749719");
Zeile gelöscht : user_pref("icqtoolbar.allowSendURL", false);
Zeile gelöscht : user_pref("icqtoolbar.engineVerified", false);
Zeile gelöscht : user_pref("icqtoolbar.firstTbRun", false);
Zeile gelöscht : user_pref("icqtoolbar.geolastmodified", 1342969627);
Zeile gelöscht : user_pref("icqtoolbar.hiddenElements", "itb_options itb_people itb_zoom_in itb_zoom_out itb_zoom_default itb_games itb_highlight");
Zeile gelöscht : user_pref("icqtoolbar.icqgeo", 49);
Zeile gelöscht : user_pref("icqtoolbar.installTime", "1342969627");
Zeile gelöscht : user_pref("icqtoolbar.numberOfSearches", 0);
Zeile gelöscht : user_pref("icqtoolbar.previousFFVersion", "13.0");
Zeile gelöscht : user_pref("icqtoolbar.showPc", false);
Zeile gelöscht : user_pref("icqtoolbar.skip_default_search", "no");
Zeile gelöscht : user_pref("icqtoolbar.suggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.uniqueID", "134288041113428806511342969627663");
Zeile gelöscht : user_pref("icqtoolbar.usageStatstTimestamp", 1342969629);
Zeile gelöscht : user_pref("icqtoolbar.version", "1.5.0");
Zeile gelöscht : user_pref("icqtoolbar.xmlEnableSuggestions", false);
Zeile gelöscht : user_pref("icqtoolbar.xmlLanguage", "de");
Zeile gelöscht : user_pref("keyword.URL", "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.5.0&q=");
*************************
AdwCleaner[R0].txt - [6471 octets] - [22/04/2014 12:52:13]
AdwCleaner[S0].txt - [6098 octets] - [22/04/2014 12:54:28]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6158 octets] ########## JRT: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Noel on 22.04.2014 at 12:59:45,76
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho502E.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho7AE5.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8472.tmp
Successfully deleted: [File] C:\Windows\syswow64\sho8879.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoB4A3.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoDB89.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoE9E2.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoEAB6.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoEDFE.tmp
Successfully deleted: [File] C:\Windows\syswow64\shoFF44.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Noel\appdata\locallow\boost_interprocess"
Successfully deleted: [Empty Folder] C:\Users\Noel\appdata\local\{2D566147-4F25-4ED7-870F-0A34989CB1D8}
Successfully deleted: [Empty Folder] C:\Users\Noel\appdata\local\{81B33A3A-CB04-4085-A60E-CAC84CB7CEB0}
Successfully deleted: [Empty Folder] C:\Users\Noel\appdata\local\{93D342CA-1B2E-48B3-99BB-8F04DE22869A}
Successfully deleted: [Empty Folder] C:\Users\Noel\appdata\local\{BC63215D-5B1D-450F-9B8B-D682847E9E8D}
Successfully deleted: [Empty Folder] C:\Users\Noel\appdata\local\{BF81BA22-4E8F-490D-93E4-C18E70D6D2CB}
Successfully deleted: [Empty Folder] C:\Users\Noel\appdata\local\{CE9200FD-19D9-4248-B03F-E226BA21B2CA}
~~~ FireFox
Emptied folder: C:\Users\Noel\AppData\Roaming\mozilla\firefox\profiles\5wkeu0ug.default\minidumps [94 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 22.04.2014 at 13:10:43,81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST log:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-04-2014
Ran by Noel (administrator) on NOEL-PC on 22-04-2014 13:15:33
Running from C:\Users\Noel\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSVC.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
() C:\Program Files\CDMA-1XDO\C+WEject.exe
(Conexant Systems Inc.) C:\Windows\system32\CxAudMsg64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
() C:\Program Files\PC Manager\bin\MonServiceUDisk.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Users\Noel\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BtStackServer.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
( ) C:\Program Files (x86)\LockKey\LockKey.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe
(Vimicro) C:\Program Files (x86)\USB Camera\VM331_STI.EXE
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2011-12-15] (Conexant Systems, Inc.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2809856 2012-01-16] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8079408 2012-05-09] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6199128 2012-05-09] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-05-09] (Lenovo)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-25] ( )
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe [507744 2011-12-20] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [331BigDog] => C:\Program Files (x86)\USB Camera\VM331_STI.EXE [548864 2011-11-24] (Vimicro)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-28] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-05-09] (Lenovo)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1259376 2011-07-28] ()
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [AVP] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1450695444-39005048-1700824554-1000\...\Run: [Power2GoExpress] => NA
HKU\S-1-5-21-1450695444-39005048-1700824554-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1450695444-39005048-1700824554-1001\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHAE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1450695444-39005048-1700824554-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\Noel\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [397632 2013-04-05] ()
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [247144 2012-10-08] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [202600 2012-10-08] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\Lenovo\Bluetooth Software\BtwProximityCP.dll
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: DivX Plus Web Player HTML5 <video> - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF NetworkProxy: "ftp", "82.192.78.244"
FF NetworkProxy: "ftp_port", 3128
FF NetworkProxy: "http", "82.192.78.244"
FF NetworkProxy: "http_port", 3128
FF NetworkProxy: "socks_remote_dns", true
FF NetworkProxy: "ssl", "82.192.78.244"
FF NetworkProxy: "ssl_port", 3128
FF NetworkProxy: "type", 1
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Noel\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\searchplugins\searchplugins-backup
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: FoxyProxy Standard - C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\Extensions\foxyproxy-basic@eric.h.jung [2014-02-11]
FF Extension: GoogleSharing - C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\Extensions\googlesharing@extension.thoughtcrime.org [2012-06-06]
FF Extension: HTTPS-Everywhere - C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\Extensions\https-everywhere@eff.org [2014-04-15]
FF Extension: Ghostery - C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\Extensions\firefox@ghostery.com.xpi [2013-08-23]
FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi [2012-11-20]
FF Extension: Adblock Plus - C:\Users\Noel\AppData\Roaming\Mozilla\Firefox\Profiles\5wkeu0ug.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2012-06-06]
FF HKLM-x32\...\Firefox\Extensions: [virtualKeyboard@kaspersky.ru] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2012\FFExt\virtualKeyboard@kaspersky.ru
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012-08-06]
FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\url_advisor@kaspersky.com [2013-07-14]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\virtual_keyboard@kaspersky.com [2013-07-14]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com
FF Extension: Content Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\content_blocker@kaspersky.com [2013-07-14]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\anti_banner@kaspersky.com [2013-07-14]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\FFExt\online_banking@kaspersky.com [2013-07-14]
==================== Services (Whitelisted) =================
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe [356128 2013-10-10] (Kaspersky Lab ZAO)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [945440 2012-02-01] (Broadcom Corporation.)
R2 CDROM_Detect; C:\Program Files\CDMA-1XDO\C+WEject.exe [269312 2011-09-07] ()
S4 DamageGuardSvc; C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe [572976 2012-02-13] (Lenovo (Beijing) Limited)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1907896 2013-10-31] (Microsoft Corporation)
R2 UDisk Monitor; C:\Program Files\PC Manager\bin\MonServiceUDisk.exe [405504 2013-05-03] ()
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2012-02-02] (Broadcom Corporation.)
S3 CT_QUALCOMM_U_drv; C:\Windows\System32\DRIVERS\CT_QUALCOMM_U_drv.sys [118016 2009-04-27] (QUALCOMM Incorporated)
S4 DamageGuard; C:\Windows\System32\DRIVERS\DamageGuardX64.sys [217392 2012-02-10] (Lenovo)
S4 dgFltr; C:\Windows\System32\drivers\dgFltrX64.sys [23648 2011-12-13] (Lenovo)
S3 Generalusbserialser20679; C:\Windows\System32\DRIVERS\CT_U_USBSER.sys [124160 2013-04-15] (Incorporated)
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2013-12-11] (Kaspersky Lab ZAO)
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [90208 2013-07-14] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [626272 2013-10-10] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-12-11] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-10] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [54368 2013-07-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178448 2013-07-14] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-04-22] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [952832 2011-12-06] (Vimicro Corporation)
U3 BcmSqlStartupSvc;
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
U2 CLKMSVC10_3A60B698;
U2 CLKMSVC10_C3B3B687;
U2 DriverService;
U2 iATAgentService;
U2 idealife Update Service;
U3 IGRS;
U2 IviRegMgr;
S3 massfilter; system32\drivers\massfilter.sys [X]
U2 Oasis2Service;
U2 PCCarerService;
U2 ReadyComm.DirectRouter;
U2 RichVideo;
U2 RtLedService;
U2 SeaPort;
U2 SoftwareService;
U3 SQLWriter;
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-22 13:15 - 2014-04-22 13:15 - 00024324 _____ () C:\Users\Noel\Desktop\FRST.txt
2014-04-22 13:15 - 2014-04-22 13:15 - 00000000 ____D () C:\Users\Noel\Desktop\FRST-OlderVersion
2014-04-22 13:10 - 2014-04-22 13:10 - 00002196 _____ () C:\Users\Noel\Desktop\JRT.txt
2014-04-22 12:59 - 2014-04-22 12:59 - 00000000 ____D () C:\Windows\ERUNT
2014-04-22 12:56 - 2014-04-22 12:56 - 00006250 _____ () C:\Users\Noel\Desktop\AdwCleaner[S0].txt
2014-04-22 12:52 - 2014-04-22 12:54 - 00000000 ____D () C:\AdwCleaner
2014-04-22 12:51 - 2014-04-22 12:51 - 01335637 _____ () C:\Users\Noel\Desktop\adwcleaner.exe
2014-04-22 12:48 - 2014-04-22 12:48 - 00007105 _____ () C:\Users\Noel\Desktop\mbam.txt
2014-04-22 12:24 - 2014-04-22 12:57 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 12:24 - 2014-04-22 12:24 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-22 12:24 - 2014-04-22 12:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 12:24 - 2014-04-22 12:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-22 12:24 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-22 12:24 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-22 12:24 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-22 12:14 - 2014-04-22 12:15 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Noel\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-21 15:48 - 2014-04-21 15:48 - 00034296 _____ () C:\Users\Noel\Documents\cycling.odt
2014-04-18 16:38 - 2014-04-22 12:17 - 00000000 ____D () C:\Users\Noel\Desktop\Antivirus
2014-04-18 11:52 - 2014-04-18 11:54 - 01016261 _____ (Thisisu) C:\Users\Noel\Desktop\JRT.exe
2014-04-17 12:14 - 2014-04-17 12:14 - 00017324 _____ () C:\ComboFix.txt
2014-04-17 11:05 - 2014-04-17 12:15 - 00000000 ____D () C:\Qoobox
2014-04-17 11:05 - 2014-04-17 12:09 - 00000000 ____D () C:\Windows\erdnt
2014-04-17 11:05 - 2011-06-26 06:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-04-17 11:05 - 2010-11-07 17:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-04-17 11:05 - 2009-04-20 04:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-04-17 11:05 - 2000-08-31 00:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-04-17 11:05 - 2000-08-31 00:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-04-17 11:05 - 2000-08-31 00:00 - 00098816 _____ () C:\Windows\sed.exe
2014-04-17 11:05 - 2000-08-31 00:00 - 00080412 _____ () C:\Windows\grep.exe
2014-04-17 11:05 - 2000-08-31 00:00 - 00068096 _____ () C:\Windows\zip.exe
2014-04-17 10:49 - 2014-04-17 10:50 - 05194807 ____R (Swearware) C:\Users\Noel\Desktop\ComboFix.exe
2014-04-16 10:13 - 2014-04-16 12:16 - 00901716 _____ () C:\Users\Noel\Documents\Leon word 16 avril.odt
2014-04-16 09:36 - 2014-04-16 09:36 - 00047980 _____ () C:\Users\Noel\Documents\Virenmail2.odt
2014-04-15 14:42 - 2014-04-16 09:37 - 00107478 _____ () C:\Users\Noel\Documents\Virenmail.odt
2014-04-15 13:15 - 2014-04-15 13:15 - 00302288 _____ () C:\Windows\Minidump\041514-19390-01.dmp
2014-04-15 13:02 - 2014-04-22 13:15 - 00000000 ____D () C:\FRST
2014-04-15 12:56 - 2014-04-22 13:15 - 02061312 _____ (Farbar) C:\Users\Noel\Desktop\FRST64.exe
2014-04-11 18:18 - 2014-04-11 18:19 - 00000000 ____D () C:\Users\Noel\Desktop\Pro evoluton soccer6
2014-04-10 16:43 - 2014-04-10 19:15 - 00000000 ____D () C:\Users\Noel\Documents\Ndarinfo
2014-04-10 11:42 - 2014-04-10 11:44 - 00000000 ____D () C:\Users\Noel\Documents\Downloads2
2014-04-09 16:27 - 2014-04-09 16:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-09 11:29 - 2014-04-22 12:21 - 00000000 ____D () C:\Users\Noel\Documents\FM Teranga
2014-04-08 15:59 - 2014-04-11 12:38 - 00017265 _____ () C:\Users\Noel\Desktop\English.odt
2014-04-06 09:14 - 2014-04-17 13:23 - 00000000 ____D () C:\Users\Noel\Documents\Bilder für Ordner
2014-04-06 09:13 - 2014-04-10 11:43 - 00000000 ____D () C:\Users\Noel\Documents\Togo Senegal
2014-04-06 09:13 - 2014-04-06 09:14 - 00000000 ____D () C:\Users\Noel\Documents\Abitur
2014-04-04 17:14 - 2014-04-07 21:33 - 00000000 ____D () C:\Users\Noel\Documents\GTA Vice City User Files
2014-04-04 17:12 - 2014-04-05 21:59 - 00000000 ____D () C:\Users\Noel\Desktop\GTA VICE CITY 5
2014-04-04 10:57 - 2014-04-09 11:21 - 00029145 _____ () C:\Users\Noel\Desktop\Email André.odt
2014-04-03 18:45 - 2014-04-15 18:03 - 00019260 _____ () C:\Users\Noel\Desktop\contest.odt
==================== One Month Modified Files and Folders =======
2014-04-22 13:15 - 2014-04-22 13:15 - 00024324 _____ () C:\Users\Noel\Desktop\FRST.txt
2014-04-22 13:15 - 2014-04-22 13:15 - 00000000 ____D () C:\Users\Noel\Desktop\FRST-OlderVersion
2014-04-22 13:15 - 2014-04-15 13:02 - 00000000 ____D () C:\FRST
2014-04-22 13:15 - 2014-04-15 12:56 - 02061312 _____ (Farbar) C:\Users\Noel\Desktop\FRST64.exe
2014-04-22 13:10 - 2014-04-22 13:10 - 00002196 _____ () C:\Users\Noel\Desktop\JRT.txt
2014-04-22 13:04 - 2009-07-14 04:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-22 13:04 - 2009-07-14 04:45 - 00032064 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-22 12:59 - 2014-04-22 12:59 - 00000000 ____D () C:\Windows\ERUNT
2014-04-22 12:58 - 2012-06-06 00:50 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-04-22 12:57 - 2014-04-22 12:24 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-22 12:57 - 2012-05-09 19:26 - 00000000 ____D () C:\ProgramData\VeriFace
2014-04-22 12:56 - 2014-04-22 12:56 - 00006250 _____ () C:\Users\Noel\Desktop\AdwCleaner[S0].txt
2014-04-22 12:56 - 2012-06-06 00:05 - 03385882 _____ () C:\FaceProv.log
2014-04-22 12:56 - 2012-05-09 19:29 - 00165314 _____ () C:\Windows\system32\fastboot.set
2014-04-22 12:56 - 2009-07-14 05:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-22 12:55 - 2012-05-09 18:44 - 02069102 _____ () C:\Windows\WindowsUpdate.log
2014-04-22 12:55 - 2009-07-14 04:51 - 00110677 _____ () C:\Windows\setupact.log
2014-04-22 12:54 - 2014-04-22 12:52 - 00000000 ____D () C:\AdwCleaner
2014-04-22 12:51 - 2014-04-22 12:51 - 01335637 _____ () C:\Users\Noel\Desktop\adwcleaner.exe
2014-04-22 12:48 - 2014-04-22 12:48 - 00007105 _____ () C:\Users\Noel\Desktop\mbam.txt
2014-04-22 12:43 - 2010-11-21 03:47 - 00066708 _____ () C:\Windows\PFRO.log
2014-04-22 12:24 - 2014-04-22 12:24 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-22 12:24 - 2014-04-22 12:24 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-22 12:24 - 2014-04-22 12:24 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-22 12:21 - 2014-04-09 11:29 - 00000000 ____D () C:\Users\Noel\Documents\FM Teranga
2014-04-22 12:17 - 2014-04-18 16:38 - 00000000 ____D () C:\Users\Noel\Desktop\Antivirus
2014-04-22 12:15 - 2014-04-22 12:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Noel\Desktop\mbam-setup-2.0.1.1004.exe
2014-04-22 12:10 - 2012-05-10 04:32 - 00707956 _____ () C:\Windows\system32\perfh007.dat
2014-04-22 12:10 - 2012-05-10 04:32 - 00153410 _____ () C:\Windows\system32\perfc007.dat
2014-04-22 12:10 - 2009-07-14 05:13 - 01643558 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-22 11:49 - 2014-01-07 09:00 - 00272156 _____ () C:\Users\Noel\Desktop\Mirja.odt
2014-04-22 11:38 - 2013-10-17 10:08 - 00000000 ____D () C:\Users\Noel\Desktop\FMBilder
2014-04-21 15:48 - 2014-04-21 15:48 - 00034296 _____ () C:\Users\Noel\Documents\cycling.odt
2014-04-20 23:21 - 2012-08-06 16:58 - 00000000 ____D () C:\Users\Noel\AppData\Roaming\vlc
2014-04-18 18:58 - 2014-01-06 09:40 - 00007607 _____ () C:\Users\Noel\AppData\Local\Resmon.ResmonCfg
2014-04-18 13:29 - 2013-03-22 17:07 - 00000000 ____D () C:\Users\Noel\Documents\Wieler
2014-04-18 13:29 - 2012-07-22 15:26 - 00000000 ____D () C:\Users\Noel\AppData\Roaming\ICQ
2014-04-18 11:54 - 2014-04-18 11:52 - 01016261 _____ (Thisisu) C:\Users\Noel\Desktop\JRT.exe
2014-04-17 16:20 - 2014-03-05 21:53 - 00000000 ____D () C:\Users\Noel\Documents\Mirja
2014-04-17 13:23 - 2014-04-06 09:14 - 00000000 ____D () C:\Users\Noel\Documents\Bilder für Ordner
2014-04-17 12:15 - 2014-04-17 11:05 - 00000000 ____D () C:\Qoobox
2014-04-17 12:15 - 2009-07-14 03:20 - 00000000 ___HD () C:\Users\Default
2014-04-17 12:14 - 2014-04-17 12:14 - 00017324 _____ () C:\ComboFix.txt
2014-04-17 12:09 - 2014-04-17 11:05 - 00000000 ____D () C:\Windows\erdnt
2014-04-17 11:55 - 2009-07-14 02:34 - 00000215 _____ () C:\Windows\system.ini
2014-04-17 10:50 - 2014-04-17 10:49 - 05194807 ____R (Swearware) C:\Users\Noel\Desktop\ComboFix.exe
2014-04-16 12:16 - 2014-04-16 10:13 - 00901716 _____ () C:\Users\Noel\Documents\Leon word 16 avril.odt
2014-04-16 09:37 - 2014-04-15 14:42 - 00107478 _____ () C:\Users\Noel\Documents\Virenmail.odt
2014-04-16 09:36 - 2014-04-16 09:36 - 00047980 _____ () C:\Users\Noel\Documents\Virenmail2.odt
2014-04-15 18:03 - 2014-04-03 18:45 - 00019260 _____ () C:\Users\Noel\Desktop\contest.odt
2014-04-15 13:15 - 2014-04-15 13:15 - 00302288 _____ () C:\Windows\Minidump\041514-19390-01.dmp
2014-04-15 13:15 - 2013-10-16 13:30 - 724202523 _____ () C:\Windows\MEMORY.DMP
2014-04-15 13:15 - 2013-10-16 13:30 - 00000000 ____D () C:\Windows\Minidump
2014-04-15 11:37 - 2014-02-10 14:47 - 00000000 ____D () C:\Users\Noel\Documents\CACIT2
2014-04-15 09:51 - 2012-06-06 01:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-12 22:57 - 2009-07-14 03:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-04-12 22:50 - 2013-10-09 16:11 - 00000000 ____D () C:\Users\Noel\AppData\Roaming\dvdcss
2014-04-11 18:19 - 2014-04-11 18:18 - 00000000 ____D () C:\Users\Noel\Desktop\Pro evoluton soccer6
2014-04-11 12:38 - 2014-04-08 15:59 - 00017265 _____ () C:\Users\Noel\Desktop\English.odt
2014-04-11 11:29 - 2013-10-04 13:55 - 00000000 ____D () C:\Users\Noel\Desktop\CACIT
2014-04-10 19:15 - 2014-04-10 16:43 - 00000000 ____D () C:\Users\Noel\Documents\Ndarinfo
2014-04-10 11:44 - 2014-04-10 11:42 - 00000000 ____D () C:\Users\Noel\Documents\Downloads2
2014-04-10 11:43 - 2014-04-06 09:13 - 00000000 ____D () C:\Users\Noel\Documents\Togo Senegal
2014-04-09 16:27 - 2014-04-09 16:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-09 11:21 - 2014-04-04 10:57 - 00029145 _____ () C:\Users\Noel\Desktop\Email André.odt
2014-04-08 17:42 - 2012-09-03 11:58 - 00000000 ____D () C:\Users\Noel\Documents\Schule S3
2014-04-08 09:58 - 2014-02-14 11:47 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-04-08 09:56 - 2013-11-06 17:38 - 00000000 ____D () C:\Program Files (x86)\SupportAppCB
2014-04-08 09:56 - 2012-05-09 18:49 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-04-08 09:54 - 2012-12-05 13:42 - 00000000 ____D () C:\ProgramData\HappyCloud
2014-04-07 21:33 - 2014-04-04 17:14 - 00000000 ____D () C:\Users\Noel\Documents\GTA Vice City User Files
2014-04-06 09:14 - 2014-04-06 09:13 - 00000000 ____D () C:\Users\Noel\Documents\Abitur
2014-04-06 09:13 - 2014-01-31 09:33 - 00000000 ____D () C:\Users\Noel\Documents\CACIT - Dossiers plaintes
2014-04-06 09:13 - 2013-03-22 17:06 - 00000000 ____D () C:\Users\Noel\Documents\Schule S4
2014-04-05 21:59 - 2014-04-04 17:12 - 00000000 ____D () C:\Users\Noel\Desktop\GTA VICE CITY 5
2014-04-04 13:35 - 2012-07-28 00:53 - 00000000 ____D () C:\Users\Noel\AppData\Roaming\Pro Cycling Manager 2012
2014-04-04 13:35 - 2012-07-28 00:31 - 00000000 ____D () C:\Users\Noel\Documents\Pro Cycling Manager 2012
2014-04-04 10:48 - 2012-07-06 10:14 - 00000000 ____D () C:\Users\Noel\Documents\Youcam
2014-04-03 09:51 - 2014-04-22 12:24 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-22 12:24 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-22 12:24 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 15:32 - 2012-12-22 17:31 - 00000000 ____D () C:\Users\Noel\AppData\Local\Microsoft Games
Some content of TEMP:
====================
C:\Users\Noel\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-16 12:59
==================== End Of Log ============================ --- --- --- |