Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Scan Date: 25.12.2014
Scan Time: 02:43:36
Logfile: Mbam.txt
Administrator: Yes
Version: 2.00.4.1028
Malware Database: v2014.12.25.01
Rootkit Database: v2014.12.23.02
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Audio Laptop
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 329647
Time Elapsed: 26 min, 59 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 5
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Delete-on-Reboot, [53b22b3c94e8c571d444bc5983802dd3],
PUP.Optional.Snapdo.T, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006EE092-9658-4FD6-BD8E-A21A348E59F5}, Quarantined, [53b22b3c94e8c571d444bc5983802dd3],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SmdmF, Quarantined, [2bdaeb7c2b51b6804eae2e411ee5966a],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, Delete-on-Reboot, [42c3e4833b412e0892e7d1cc8e757f81],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, Delete-on-Reboot, [f015db8cc4b878beeba9e2d137cd2dd3],
Registry Values: 4
PUP.Optional.SmartBar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, Quarantined, [c93c6ff82b5178be05e86903c043867a]
PUP.Optional.SmartBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\TOOLBAR|{ae07101b-46d4-4a98-af68-0333ea26e113}, Smartbar, Quarantined, [c2434720d7a52115e508155704ff33cd]
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0P1C2R1R1D0W0O0R1I1M, Delete-on-Reboot, [f015db8cc4b878beeba9e2d137cd2dd3]
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {006ee092-9658-4fd6-bd8e-a21a348e59f5}, Delete-on-Reboot, [80855215413b63d30d7b3a3c8e75e11f]
Registry Data: 5
PUP.Optional.HelperBar.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cpk3SmoxYhkwMtt-Tugg,,&q={searchTerms}, Good: (Google), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cpk3SmoxYhkwMtt-Tugg,,&q={searchTerms}),Replaced,[cd38d1968af23ff73a04a4cefb0a38c8]
PUP.Optional.DefaultSearch.A, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, Search, Good: (Google), Bad: (Search,[ef16c6a1cbb14beb46472f421fe66e92]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cplFK6l34sOqa8e1F57A,,&q={searchTerms}, Good: (Google), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cplFK6l34sOqa8e1F57A,,&q={searchTerms}),Del ete-on-Reboot,[a65f7beccdafd06689ba6111699c8c74]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cplFK6l34sOqa8e1F57A,,&q={searchTerms}, Good: (Google), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cplFK6l34sOqa8e1F57A,,&q={searchTerms}),Del ete-on-Reboot,[a95cb4b3c0bc70c6a4a0472b13f236ca]
PUP.Optional.HelperBar.A, HKU\S-1-5-21-1567850050-3633006235-1092218065-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cplFK6l34sOqa8e1F57A,,&q={searchTerms}, Good: (Google), Bad: (hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7e_PC43ATEq6zp0PVBSktOwkyFOGCXEm4IakSBsl6uQBMq5Yz0bWb0xjHgq4Ge9nqyYqOlAvbg57cplFK6l34sOqa8e1F57A,,&q={searchTerms}),Del ete-on-Reboot,[976ee681f28af244dc63234fc63f8977]
Folders: 3
PUP.Optional.OpenCandy, C:\Users\Audio Laptop\AppData\Roaming\OpenCandy, Quarantined, [15f082e5493344f296e64dd88182b44c],
PUP.Optional.OpenCandy, C:\Users\Audio Laptop\AppData\Roaming\OpenCandy\07F7904614C9418BBF002B6B20383FAD, Quarantined, [15f082e5493344f296e64dd88182b44c],
PUP.Optional.OpenCandy, C:\Users\Audio Laptop\AppData\Roaming\OpenCandy\FA8C1AF4D642461C8C7737DFBE36546A, Quarantined, [15f082e5493344f296e64dd88182b44c],
Files: 5
PUP.Optional.OpenCandy, C:\Users\Audio Laptop\Downloads\DTLite4491-0356.exe, Quarantined, [b94c3f289ede3df9fd3baaf82fd624dc],
PUP.Optional.AZLyrics.A, C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage, Quarantined, [9471a1c68fed2214b2db2c31c63d9e62],
PUP.Optional.AZLyrics.A, C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_www.azlyrics.com_0.localstorage-journal, Quarantined, [b64f93d43e3e90a6117ce97443c0b44c],
PUP.Optional.OpenCandy, C:\Users\Audio Laptop\AppData\Roaming\OpenCandy\07F7904614C9418BBF002B6B20383FAD\Installer.exe, Quarantined, [15f082e5493344f296e64dd88182b44c],
PUP.Optional.OpenCandy, C:\Users\Audio Laptop\AppData\Roaming\OpenCandy\FA8C1AF4D642461C8C7737DFBE36546A\TuneUp2014GER1day-de-DE-p4v1.exe, Quarantined, [15f082e5493344f296e64dd88182b44c],
Physical Sectors: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v4.106 - Bericht erstellt am 25/12/2014 um 03:38:10
# Aktualisiert 21/12/2014 von Xplode
# Database : 2014-12-21.4 [Live]
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits)
# Benutzername : Audio Laptop - AUDIOLAPTOP
# Gestartet von : C:\Users\Audio Laptop\Downloads\AdwCleaner_4.106.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Audio Laptop\AppData\Roaming\Solvusoft
Datei Gelöscht : C:\Windows\System32\roboot64.exe
Datei Gelöscht : C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage
Datei Gelöscht : C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_static.audienceinsights.net_0.localstorage-journal
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Audio Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2492}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.de
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17496
-\\ Google Chrome v39.0.2171.95
*************************
AdwCleaner[R0].txt - [3028 octets] - [25/12/2014 03:34:53]
AdwCleaner[S0].txt - [2638 octets] - [25/12/2014 03:38:10]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2698 octets] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.0 (11.29.2014:1)
OS: Windows 7 Ultimate x64
Ran by Audio Laptop on 25.12.2014 at 3:51:19,19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.12.2014 at 3:58:50,00
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-12-2014 01
Ran by Audio Laptop (administrator) on AUDIOLAPTOP on 25-12-2014 04:01:23
Running from C:\Users\Audio Laptop\Downloads
Loaded Profile: Audio Laptop (Available profiles: Audio Laptop)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Prevx) C:\Program Files\Prevx\prevx.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(RemoteMouse.net) C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe
(Prevx) C:\Program Files\Prevx\prevx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Synchro Arts Ltd) C:\Program Files (x86)\Common Files\Synchro Arts Shared\License.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642304 2013-04-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [AMD AVT] => C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe [20992 2012-03-19] ()
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [124208 2014-10-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3653136 2014-11-09] (AVG Technologies CZ, s.r.o.)
HKU\S-1-5-21-1567850050-3633006235-1092218065-1000\...\Run: [Remote Mouse] => C:\Program Files (x86)\Remote Mouse\RemoteMouse.exe [2043904 2014-09-29] (RemoteMouse.net)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-08-13] (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1567850050-3633006235-1092218065-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1567850050-3633006235-1092218065-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
Chrome:
=======
CHR HomePage: Default -> hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb_6i_xGmHax17vI5L2_MCWmPo0KNcoOH-LcL8AHWHymiJGqDcczqdKZJDqmd4qic7S3KcBqBHEXTzJwoFJMlSgg1lMP78ItVRMzbIEJ7O6T7vxei77YUdgi1ykaZKuZozu0CGpXMxeFNplsAc6A9-ucOmrcpht6A,,
CHR StartupUrls: Default -> "https://www.google.de/"
CHR Profile: C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-23]
CHR Extension: (Google Drive) - C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-23]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-06]
CHR Extension: (YouTube) - C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-23]
CHR Extension: (Google-Suche) - C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-23]
CHR Extension: (Google Wallet) - C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-23]
CHR Extension: (Google Mail) - C:\Users\Audio Laptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-23]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-09] (Avira Operations GmbH & Co. KG)
S2 avgfws; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [1486664 2014-11-09] (AVG Technologies CZ, s.r.o.)
S2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3488784 2014-11-09] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-11-09] (AVG Technologies CZ, s.r.o.)
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [164656 2014-10-22] (Avira Operations GmbH & Co. KG)
R2 CSIScanner; C:\Program Files\Prevx\prevx.exe [6746280 2014-12-01] (Prevx)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Synchro Arts License Manager; C:\Program Files (x86)\Common Files\Synchro Arts Shared\License.exe [175488 2008-02-22] (Synchro Arts Ltd) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AKAI_ACV0_MIDI; C:\Windows\System32\drivers\akaiacv0m.sys [53880 2014-09-27] (Ploytec GmbH)
S3 AKAI_ACV0_USB; C:\Windows\System32\Drivers\akaiacv0u.sys [502392 2014-09-27] (Ploytec GmbH)
S3 AKAI_ACV0_WDM; C:\Windows\System32\drivers\akaiacv0a.sys [56952 2014-09-27] (Numark)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\System32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [263960 2014-10-29] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-11-06] (Avira Operations GmbH & Co. KG)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [274200 2014-10-10] (AVG Technologies CZ, s.r.o.)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-11-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-07-02] (Avira Operations GmbH & Co. KG)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-07-23] (Disc Soft Ltd)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-12-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-11-21] (Malwarebytes Corporation)
R3 pxkbf; C:\Windows\System32\drivers\pxkbf.sys [24024 2014-12-01] (Prevx)
R1 pxrts; C:\Windows\System32\drivers\pxrts.sys [65736 2014-12-01] (Prevx)
R0 pxscan; C:\Windows\System32\drivers\pxscan.sys [36384 2014-12-01] (Prevx)
S3 synusb64; C:\Windows\System32\DRIVERS\synusb64.sys [30352 2011-12-14] (Steinberg Media Technologies GmbH)
S3 Tosrfcom; No ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-25 03:58 - 2014-12-25 03:58 - 00000628 _____ () C:\Users\Audio Laptop\Desktop\JRT.txt
2014-12-25 03:51 - 2014-12-25 03:51 - 00000000 ____D () C:\Windows\ERUNT
2014-12-25 03:48 - 2014-12-25 03:48 - 01707646 _____ (Thisisu) C:\Users\Audio Laptop\Downloads\JRT.exe
2014-12-25 03:31 - 2014-12-25 03:38 - 00000000 ____D () C:\AdwCleaner
2014-12-25 03:29 - 2014-12-25 03:30 - 02173952 _____ () C:\Users\Audio Laptop\Downloads\AdwCleaner_4.106.exe
2014-12-25 03:13 - 2014-12-25 03:29 - 00007560 _____ () C:\Users\Audio Laptop\Desktop\Mbam.txt
2014-12-23 13:47 - 2014-12-23 14:03 - 00000000 ____D () C:\Users\Audio Laptop\Desktop\Derya Dügün
2014-12-23 13:01 - 2014-12-23 13:03 - 00000000 ____D () C:\Users\Audio Laptop\Desktop\NX30 Bilder
2014-12-23 12:44 - 2014-12-23 12:46 - 00028416 _____ () C:\Users\Audio Laptop\Downloads\Addition.txt
2014-12-23 12:42 - 2014-12-25 04:01 - 00011571 _____ () C:\Users\Audio Laptop\Downloads\FRST.txt
2014-12-23 12:42 - 2014-12-23 12:42 - 00000000 ____D () C:\Users\Audio Laptop\Downloads\FRST-OlderVersion
2014-12-18 15:09 - 2014-12-23 12:41 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\Spotify
2014-12-18 15:09 - 2014-12-18 15:10 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Local\Spotify
2014-12-18 15:09 - 2014-12-18 15:09 - 00001843 _____ () C:\Users\Audio Laptop\Desktop\Spotify.lnk
2014-12-18 15:09 - 2014-12-18 15:09 - 00001829 _____ () C:\Users\Audio Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2014-12-18 15:08 - 2014-12-18 15:08 - 00137888 _____ (Spotify Ltd) C:\Users\Audio Laptop\Downloads\SpotifySetup.exe
2014-12-18 15:03 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-18 15:03 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-12-17 23:01 - 2014-12-17 23:01 - 00000000 ____D () C:\Windows\pss
2014-12-17 20:55 - 2014-12-25 03:43 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-12-17 20:32 - 2014-12-17 20:32 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-12-17 20:32 - 2014-12-17 20:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-12-17 20:32 - 2014-12-17 20:32 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-12-17 20:32 - 2014-12-17 20:32 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-12-17 20:32 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-12-17 20:32 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-12-17 20:32 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-12-17 20:31 - 2014-12-17 20:31 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Audio Laptop\Downloads\mbam-setup-2.0.4.1028.exe
2014-12-17 19:58 - 2014-12-17 20:01 - 00000000 ___SD () C:\32788R22FWJFW
2014-12-17 19:24 - 2014-12-17 19:59 - 00000000 ___SD () C:\ComboFix
2014-12-17 19:22 - 2014-12-17 19:22 - 05601641 ____R (Swearware) C:\Users\Audio Laptop\Desktop\ComboFix.exe
2014-12-17 16:52 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-12-17 16:52 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-12-17 16:52 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-12-17 16:52 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-12-17 16:52 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-12-17 16:52 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-12-17 16:52 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-12-17 16:52 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-12-17 16:48 - 2014-12-17 16:52 - 00000000 ____D () C:\Qoobox
2014-12-17 16:48 - 2014-12-17 16:48 - 00000000 ____D () C:\Windows\erdnt
2014-12-17 16:47 - 2014-12-17 16:47 - 05601641 ____R (Swearware) C:\Users\Audio Laptop\Downloads\ComboFix.exe
2014-12-17 16:43 - 2014-12-17 16:43 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Audio Laptop\Downloads\revosetup95 (1).exe
2014-12-17 16:18 - 2014-12-17 16:18 - 00000371 _____ () C:\Users\Audio Laptop\Downloads\restartExplorer.zip
2014-12-17 15:59 - 2014-12-17 15:59 - 00000000 ____D () C:\Windows\system32\appraiser
2014-12-17 15:48 - 2014-12-17 15:49 - 00036525 _____ () C:\Users\Audio Laptop\Desktop\Addition.txt
2014-12-17 15:46 - 2014-12-25 04:01 - 00000000 ____D () C:\FRST
2014-12-17 15:46 - 2014-12-17 15:49 - 00035123 _____ () C:\Users\Audio Laptop\Desktop\FRST.txt
2014-12-17 15:45 - 2014-12-23 12:42 - 02122240 _____ (Farbar) C:\Users\Audio Laptop\Downloads\FRST64.exe
2014-12-17 15:35 - 2014-12-17 15:35 - 00015885 _____ () C:\Users\Audio Laptop\Documents\tencu etwas neues.odt
2014-12-17 03:01 - 2014-10-18 03:05 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-12-17 03:01 - 2014-10-18 02:33 - 03209728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-12-17 03:01 - 2014-07-07 03:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-12-17 03:01 - 2014-07-07 03:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-12-17 03:01 - 2014-07-07 03:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-12-17 03:01 - 2014-07-07 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-12-17 03:01 - 2014-07-07 02:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-12-17 03:01 - 2014-07-07 02:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-12-17 03:01 - 2014-07-07 02:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-12-17 03:01 - 2014-07-07 02:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-12-16 16:44 - 2014-12-04 03:50 - 00830976 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2014-12-16 16:44 - 2014-12-04 03:50 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2014-12-16 16:44 - 2014-12-04 03:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-16 16:44 - 2014-12-04 03:50 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2014-12-16 16:44 - 2014-12-04 03:50 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-16 16:44 - 2014-12-04 03:50 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2014-12-16 16:44 - 2014-12-04 03:44 - 01083392 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-16 16:44 - 2014-12-02 00:28 - 01232040 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2014-12-16 16:44 - 2014-11-27 02:43 - 00389296 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-16 16:44 - 2014-11-27 02:10 - 00342200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-12-16 16:44 - 2014-11-22 04:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-16 16:44 - 2014-11-22 04:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-16 16:44 - 2014-11-22 03:50 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-16 16:44 - 2014-11-22 03:49 - 02885120 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-16 16:44 - 2014-11-22 03:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-16 16:44 - 2014-11-22 03:41 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-16 16:44 - 2014-11-22 03:40 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-16 16:44 - 2014-11-22 03:35 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-16 16:44 - 2014-11-22 03:26 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-16 16:44 - 2014-11-22 03:22 - 19749376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-12-16 16:44 - 2014-11-22 03:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-12-16 16:44 - 2014-11-22 03:14 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-16 16:44 - 2014-11-22 03:07 - 00501248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-12-16 16:44 - 2014-11-22 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-12-16 16:44 - 2014-11-22 03:06 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-12-16 16:44 - 2014-11-22 03:05 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-16 16:44 - 2014-11-22 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-12-16 16:44 - 2014-11-22 03:01 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-12-16 16:44 - 2014-11-22 02:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-12-16 16:44 - 2014-11-22 02:58 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-12-16 16:44 - 2014-11-22 02:56 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-12-16 16:44 - 2014-11-22 02:54 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-12-16 16:44 - 2014-11-22 02:49 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-16 16:44 - 2014-11-22 02:49 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-16 16:44 - 2014-11-22 02:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-16 16:44 - 2014-11-22 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-12-16 16:44 - 2014-11-22 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-12-16 16:44 - 2014-11-22 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-12-16 16:44 - 2014-11-22 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-12-16 16:44 - 2014-11-22 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-12-16 16:44 - 2014-11-22 02:29 - 04299264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-12-16 16:44 - 2014-11-22 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-12-16 16:44 - 2014-11-22 02:22 - 02052096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-12-16 16:44 - 2014-11-22 02:21 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-12-16 16:44 - 2014-11-22 02:15 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-16 16:44 - 2014-11-22 02:13 - 12836864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-12-16 16:44 - 2014-11-22 02:03 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-16 16:44 - 2014-11-22 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-12-16 16:44 - 2014-11-22 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-12-16 16:44 - 2014-11-22 01:54 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-12-16 16:44 - 2014-11-11 04:09 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-16 16:44 - 2014-11-11 03:44 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2014-12-16 16:44 - 2014-11-11 02:46 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-12-16 16:43 - 2014-11-22 04:13 - 25059840 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-16 16:43 - 2014-11-22 03:50 - 00580096 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-16 16:43 - 2014-11-22 03:48 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-16 16:43 - 2014-11-22 03:37 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-16 16:43 - 2014-11-22 03:34 - 06039552 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-16 16:43 - 2014-11-22 03:34 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-16 16:43 - 2014-11-22 03:22 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-16 16:43 - 2014-11-22 03:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-16 16:43 - 2014-11-22 03:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-16 16:43 - 2014-11-22 02:47 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-16 16:43 - 2014-11-22 02:43 - 14412800 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-16 16:43 - 2014-11-22 02:28 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-16 16:43 - 2014-11-08 04:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-16 16:43 - 2014-11-08 03:45 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-12-16 16:43 - 2014-10-30 03:03 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\charmap.exe
2014-12-16 16:43 - 2014-10-30 02:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\charmap.exe
2014-12-16 16:43 - 2014-10-03 03:12 - 02020352 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-12-16 16:43 - 2014-10-03 03:12 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2014-12-16 16:43 - 2014-10-03 03:12 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2014-12-16 16:43 - 2014-10-03 03:12 - 00181248 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2014-12-16 16:43 - 2014-10-03 03:11 - 00266240 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2014-12-16 16:43 - 2014-10-03 02:45 - 01177088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2014-12-16 16:43 - 2014-10-03 02:45 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2014-12-16 16:43 - 2014-10-03 02:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2014-12-16 16:43 - 2014-10-03 02:45 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2014-12-16 16:43 - 2014-10-03 02:44 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2014-12-08 16:28 - 2014-12-08 16:59 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\Mp3tag
2014-12-08 16:28 - 2014-12-08 16:28 - 00000983 _____ () C:\Users\Audio Laptop\Mp3tag.lnk
2014-12-08 16:28 - 2014-12-08 16:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2014-12-08 16:27 - 2014-12-08 16:28 - 00000000 ____D () C:\Program Files (x86)\Mp3tag
2014-12-08 16:27 - 2014-12-08 16:27 - 02209056 _____ () C:\Users\Audio Laptop\Downloads\avira-eu-cleaner_de.exe
2014-12-08 16:27 - 2014-12-08 16:27 - 02209056 _____ () C:\Users\Audio Laptop\Downloads\avira-eu-cleaner_de (1).exe
2014-12-08 16:26 - 2014-12-08 16:26 - 02705808 _____ () C:\Users\Audio Laptop\Downloads\mp3tagv265asetup.exe
2014-12-06 17:03 - 2014-12-06 17:03 - 00000000 ____D () C:\Users\Audio Laptop\hafti
2014-12-06 16:15 - 2014-12-06 17:00 - 379099347 _____ () C:\Users\Audio Laptop\Downloads\HARURORE_FL.rar
2014-12-01 01:54 - 2014-12-01 01:55 - 04579240 _____ (AVG Technologies) C:\Users\Audio Laptop\Downloads\avg_avct_stb_all_2015_5315_evol1.exe
2014-12-01 01:40 - 2014-12-01 01:41 - 32507072 _____ (Microsoft Corporation) C:\Users\Audio Laptop\Downloads\Windows-KB890830-x64-V5.18.exe
2014-12-01 01:36 - 2014-12-01 01:43 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\ImgBurn
2014-12-01 01:28 - 2014-12-01 01:28 - 00001881 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
2014-12-01 01:28 - 2014-12-01 01:28 - 00001869 _____ () C:\Users\Audio Laptop\ImgBurn.lnk
2014-12-01 01:28 - 2014-12-01 01:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
2014-12-01 01:28 - 2014-12-01 01:28 - 00000000 ____D () C:\Program Files (x86)\ImgBurn
2014-12-01 01:24 - 2014-12-01 01:27 - 737148928 _____ () C:\Users\Audio Laptop\Downloads\xubuntu-12.04.4-desktop-i386.iso
2014-12-01 01:12 - 2014-12-01 01:13 - 00000000 ____D () C:\ProgramData\PrevxCSI
2014-12-01 01:12 - 2014-12-01 01:12 - 00945272 _____ (Prevx) C:\Users\Audio Laptop\Downloads\prevxcsifree.exe
2014-12-01 01:12 - 2014-12-01 01:12 - 00065736 _____ (Prevx) C:\Windows\system32\Drivers\pxrts.sys
2014-12-01 01:12 - 2014-12-01 01:12 - 00062976 _____ (Prevx) C:\Windows\SysWOW64\PxSecure.dll
2014-12-01 01:12 - 2014-12-01 01:12 - 00036384 _____ (Prevx) C:\Windows\system32\Drivers\pxscan.sys
2014-12-01 01:12 - 2014-12-01 01:12 - 00024024 _____ (Prevx) C:\Windows\system32\Drivers\pxkbf.sys
2014-12-01 01:12 - 2014-12-01 01:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prevx 3.0
2014-12-01 01:12 - 2014-12-01 01:12 - 00000000 ____D () C:\Program Files\Prevx
2014-12-01 00:12 - 2014-12-17 19:20 - 00001268 _____ () C:\Users\Audio Laptop\Desktop\Revo Uninstaller.lnk
2014-12-01 00:12 - 2014-12-17 19:20 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-12-01 00:11 - 2014-12-01 00:11 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Audio Laptop\Downloads\revosetup95.exe
2014-11-30 23:57 - 2014-11-30 23:57 - 00000000 __SHD () C:\Users\Audio Laptop\AppData\Local\EmieUserList
2014-11-30 23:57 - 2014-11-30 23:57 - 00000000 __SHD () C:\Users\Audio Laptop\AppData\Local\EmieSiteList
2014-11-30 23:57 - 2014-11-30 23:57 - 00000000 __SHD () C:\Users\Audio Laptop\AppData\Local\EmieBrowserModeList
2014-11-30 23:56 - 2014-11-30 23:56 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\Adobe
2014-11-30 23:38 - 2014-11-30 23:38 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\AVG2015
2014-11-30 23:37 - 2014-12-01 01:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2014-11-30 23:37 - 2014-11-30 23:44 - 00000000 ____D () C:\ProgramData\AVG2015
2014-11-30 23:37 - 2014-11-30 23:37 - 00000981 _____ () C:\Users\Public\Desktop\AVG 2015.lnk
2014-11-30 23:37 - 2014-11-30 23:37 - 00000000 ___HD () C:\$AVG
2014-11-30 23:36 - 2014-11-30 23:36 - 00000000 ____D () C:\Program Files (x86)\AVG
2014-11-30 23:33 - 2014-12-25 02:21 - 00000000 ____D () C:\ProgramData\MFAData
2014-11-30 23:33 - 2014-11-30 23:39 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Local\Avg2015
2014-11-30 23:33 - 2014-11-30 23:33 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Local\MFAData
2014-11-30 23:31 - 2014-11-30 23:32 - 161258928 _____ (AVG Technologies) C:\Users\Audio Laptop\Downloads\avg_free_x86_all_2015_5557a8402.exe
2014-11-30 23:23 - 2014-11-30 23:23 - 10181710 _____ () C:\Users\Audio Laptop\Downloads\Black Panther ML BP 2card_combo_v1.347.zip
2014-11-25 22:54 - 2014-11-25 23:38 - 00014296 _____ () C:\Users\Audio Laptop\Documents\Früher war ich gangster doch schmeiß das bei seite.odt
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-12-25 03:59 - 2014-07-23 21:57 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-25 03:50 - 2009-07-14 05:45 - 00020672 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-25 03:50 - 2009-07-14 05:45 - 00020672 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-25 03:41 - 2014-07-23 22:09 - 00001358 _____ () C:\Users\Audio Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-12-25 03:41 - 2014-07-23 21:57 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-25 03:40 - 2014-07-19 15:16 - 00350732 _____ () C:\Windows\PFRO.log
2014-12-25 03:40 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-25 03:40 - 2009-07-14 05:51 - 00034593 _____ () C:\Windows\setupact.log
2014-12-25 03:38 - 2014-07-19 13:52 - 01533662 _____ () C:\Windows\WindowsUpdate.log
2014-12-25 03:16 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\schemas
2014-12-23 14:26 - 2014-11-16 22:46 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\vlc
2014-12-23 13:05 - 2009-07-14 18:58 - 00699440 _____ () C:\Windows\system32\perfh007.dat
2014-12-23 13:05 - 2009-07-14 18:58 - 00149548 _____ () C:\Windows\system32\perfc007.dat
2014-12-23 13:05 - 2009-07-14 06:13 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-12-17 21:00 - 2014-11-18 22:14 - 00000000 ____D () C:\Program Files\FileViewPro
2014-12-17 20:11 - 2014-08-08 09:43 - 00000000 ____D () C:\Users\Audio Laptop\Desktop\Musik Produktion
2014-12-17 20:11 - 2014-07-19 13:56 - 00000000 ____D () C:\Users\Audio Laptop
2014-12-17 20:09 - 2014-11-22 12:32 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\HpUpdate
2014-12-17 19:21 - 2014-07-24 01:05 - 00001437 _____ () C:\Users\Audio Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-12-17 19:21 - 2014-07-23 21:58 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-17 18:09 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-12-17 15:59 - 2014-07-23 22:55 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-12-17 15:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-12-17 15:59 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-12-17 15:43 - 2014-07-24 02:15 - 00000000 ____D () C:\Windows\system32\MRT
2014-12-17 15:39 - 2014-07-24 02:15 - 112710672 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-12-01 00:21 - 2014-11-22 12:42 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\1H1Q1V1N1N1S1R
2014-11-30 23:37 - 2014-07-23 22:12 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Roaming\TuneUp Software
2014-11-26 16:41 - 2014-07-23 21:56 - 00000000 ____D () C:\Users\Audio Laptop\AppData\Local\Google
Some content of TEMP:
====================
C:\Users\Audio Laptop\AppData\Local\Temp\avgnt.exe
C:\Users\Audio Laptop\AppData\Local\Temp\Quarantine.exe
C:\Users\Audio Laptop\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-12-16 17:42
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
danke und schöne feiertage