Hotmedusa | 19.04.2015 17:12 | Hi,
hier erst mal das Malwarebytes-Suchlauf-Ergebnis:
(er meldete über 60 Funde, die hier aber nicht aufgeführt sind. Du wirst schon wissen, warum. Ich versteh das ja eh nicht....) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 19.04.2015
Suchlauf-Zeit: 15:20:39
Logdatei: mbam-log01.txt
Administrator: Ja
Version: 2.01.4.1018
Malware Datenbank: v2015.04.19.03
Rootkit Datenbank: v2015.03.31.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x86
Dateisystem: NTFS
Benutzer: srmdis
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 433523
Verstrichene Zeit: 38 Min, 54 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente gefunden)
Module: 0
(Keine schädliche Elemente gefunden)
Registrierungsschlüssel: 28
PUP.Optional.Delta.A, HKLM\SOFTWARE\CLASSES\APPID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}, , [78f7036b800add59b7dc0c6ca65de41c],
PUP.Optional.Babylon.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}, , [115e412d6e1c55e1b185a59a4db6e020],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{5D79F641-C168-40DF-A32F-BACEA7509E75}, , [85ea195518720036318c48f9f80bb947],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{5D79F641-C168-40DF-A32F-BACEA7509E75}, , [85ea195518720036318c48f9f80bb947],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{A235E1E3-6296-4710-AF39-104A7FAA6C7C}, , [501f19550486d363e1ccc180d92a629e],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{A235E1E3-6296-4710-AF39-104A7FAA6C7C}, , [501f19550486d363e1ccc180d92a629e],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{C98D5B61-B0EA-4D48-9839-1079D352D880}, , [056ae985a1e930062b9584bdf40fd828],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C98D5B61-B0EA-4D48-9839-1079D352D880}, , [056ae985a1e930062b9584bdf40fd828],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}, , [3936b3bb6129cd69cef3271afa0928d8],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CB41FC95-F1B3-4797-8BB6-1012FF62ABBA}, , [3936b3bb6129cd69cef3271afa0928d8],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{F236CA79-3123-4AFB-9F74-E98117AD5625}, , [c0afe38b4a4060d68724aa970ff4b64a],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{F236CA79-3123-4AFB-9F74-E98117AD5625}, , [c0afe38b4a4060d68724aa970ff4b64a],
PUP.Optional.Mindspark.A, HKLM\SOFTWARE\FromDocToPDF_65, , [84eb2b431d6d78be5e09a797f41133cd],
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\BonanzaDealsLive, , [a9c6f27cbdcd61d58b27f33822e3d030],
PUP.Optional.DigitalSites.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\DSiteProducts, , [036c1b535e2ccb6b0617e467ce37d22e],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\FromDocToPDF_65, , [006fef7f74169d996107bc82976ece32],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, , [74fb90de177346f092135de3bc49a957],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\APPDATALOW\SOFTWARE\FromDocToPDF_65, , [670876f866247bbb0d9a599c91729a66],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\APPDATALOW\SOFTWARE\TelevisionFanatic, , [442bbdb1cfbbb87e386b5a9b7d86eb15],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\INSTALLCORE\1I1T1Q1S, , [6d02f97566249e9801e5fc11e81cea16],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\INSTALLCORE, , [86e978f60486c6703583121117ee936d],
PUP.Optional.BonanzaDeals.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\BonanzaDealsLive, , [006f7bf3b3d73df9a60c5fccf3122cd4],
PUP.Optional.CrossRider.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\APPDATALOW\SOFTWARE\Crossrider, , [fa75234b781249ed13ba9c9b7d8803fd],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, , [09665e10e4a64fe701a4da66af56ff01],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\APPDATALOW\SOFTWARE\FromDocToPDF_65, , [a2cddd91f39782b4d2d51cd99c67e917],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\APPDATALOW\SOFTWARE\TelevisionFanatic, , [28476c020e7c86b01093a64fac5708f8],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-501\SOFTWARE\APPDATALOW\SOFTWARE\FromDocToPDF_65, , [a5ca195504860b2be0c7c62fbd46e719],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-501\SOFTWARE\APPDATALOW\SOFTWARE\TelevisionFanatic, , [c4ab1b53602a3006594ae510dc27f10f],
Registrierungswerte: 6
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS\{0696f815-a3a9-490a-bb14-9ec3350b1276}, , [492689e5ec9e2016378476cb2dd6c040],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\INTERNET EXPLORER\URLSEARCHHOOKS|{0696F815-A3A9-490A-BB14-9EC3350B1276}, , [492689e5ec9e2016378476cb2dd6c040],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\INSTALLCORE|tb, 0L1N1H2O1S, , [86e978f60486c6703583121117ee936d]
PUP.Optional.Babylon.A, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}|FaviconURL, search.babylon.com/favicon.ico, , [a6c9521c7911fd39711b1c3528dd9d63]
Trojan.Agent, HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [195685e98307b97dbd6ed45c2dd8837d]
Trojan.Agent, HKU\S-1-5-21-4203143292-2018196265-3648757700-1004\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Updater, C:\ProgramData\Updater\updater.exe, , [0768adc1dbafc670bf6ca18f07fe4fb1]
Registrierungsdaten: 0
(Keine schädliche Elemente gefunden)
Ordner: 7
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers, , [b4bbef7f0387300653a9c0cdf40f55ab],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\ChromeHelper, , [b4bbef7f0387300653a9c0cdf40f55ab],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\FirefoxHelper, , [b4bbef7f0387300653a9c0cdf40f55ab],
PUP.Optional.Searchagent, C:\ProgramData\RHelpers\IeHelper, , [b4bbef7f0387300653a9c0cdf40f55ab],
PUP.Optional.Mindspark.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\extensions\65ffxtbr@FromDocToPDF_65.com, , [84eb6b039feb290d50d86b5121e28c74],
PUP.Optional.Mindspark.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF, , [84eb6b039feb290d50d86b5121e28c74],
Dateien: 22
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe, , [a6c93e303b4f3402bb9f4cf240c058a8],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\FirefoxHelper\FirefoxHelper.exe, , [5a158ae412782d09cd8d7cc2fe0251af],
PUP.Optional.MultiExtension.A, C:\ProgramData\RHelpers\IeHelper\IeHelper.exe, , [ef80ff6fcac0d165e27863db4ab69070],
PUP.Optional.VIT, C:\Users\srmdis\Downloads\installer_pou_for_pc_1_2_6_Deutsch.exe, , [0768de907b0f0234e4a283c2f809c937],
PUP.Optional.MyWebSearch.A, C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\searchplugins\my-web-search.xml, , [b2bd6a0463273105865737ba9f64d729],
PUP.Optional.Babylon.A, C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\searchplugins\babylon.xml, , [acc3b0be0783082e1376d2318480a759],
PUP.Optional.BProtector.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\bprotector_extensions.sqlite, , [2b443e3067236fc7d7be44bfaf5508f8],
PUP.Optional.BProtector.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\bprotector_prefs.js, , [4b24c0ae058590a650460ef5a163946c],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\searchplugins\delta.xml, , [5b14511dd5b5b6808a2f7a89c3419769],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared\Delta.ico, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared\BabMaint.exe, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared\BUSolution.dll, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared\chu.js, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared\GUninstaller.exe, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared\SetupParams.ini, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Delta.A, C:\Users\srmdis\AppData\Roaming\BabSolution\Shared\sqlite3.dll, , [f47b5618642665d114f19fa2867ff907],
PUP.Optional.Mindspark.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF\manifest.mf, , [84eb6b039feb290d50d86b5121e28c74],
PUP.Optional.Mindspark.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF\zigbert.rsa, , [84eb6b039feb290d50d86b5121e28c74],
PUP.Optional.Mindspark.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\extensions\65ffxtbr@FromDocToPDF_65.com\META-INF\zigbert.sf, , [84eb6b039feb290d50d86b5121e28c74],
PUP.Optional.SearchGol.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.startup.homepage", "hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6A500022FA1EA5E2&affID=119357&tt=240913_246&tsp=5019");), ,[5b148ce2c1c962d439def94822e4728e]
PUP.Optional.SearchGol.A, C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\prefs.js, Gut: (), Schlecht: (user_pref("browser.newtab.url", "hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=6A500022FA1EA5E2&affID=119357&tt=240913_246&tsp=5019");), ,[056ab7b70387ae88ad9b6dd445c106fa]
PUP.Optional.CrossRider.A, C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.crossrider.bic", "142844f0c903b98c02adadfe77910329");), ,[f778620cbcce171f45919da35aacc13f]
Physische Sektoren: 0
(Keine schädliche Elemente gefunden)
(end) Ergebnis Adw-Cleaner: Code:
# AdwCleaner v4.201 - Bericht erstellt 19/04/2015 um 17:27:47
# Aktualisiert 08/04/2015 von Xplode
# Datenbank : 2015-04-08.1 [Lokal]
# Betriebssystem : Windows Vista (TM) Home Premium Service Pack 2 (x86)
# Benutzername : srmdis - MEINKLAPPTOP
# Gestarted von : C:\Users\srmdis\Downloads\AdwCleaner_4.201(1).exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\srmdis\AppData\LocalLow\Toolbar4
Ordner Gelöscht : C:\Users\srmdis\AppData\Roaming\BabSolution
Ordner Gelöscht : C:\Users\srmdis\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\srmdis\AppData\Roaming\digitalsite
Ordner Gelöscht : C:\Users\srmdis\AppData\Roaming\DigitalSites
Ordner Gelöscht : C:\Users\srmdis\AppData\Roaming\registry mechanic
Ordner Gelöscht : C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\Extensions\65ffxtbr@FromDocToPDF_65.com
Datei Gelöscht : C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\bprotector_extensions.rdf
Datei Gelöscht : C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\bprotector_extensions.sqlite
Datei Gelöscht : C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\bprotector_prefs.js
Datei Gelöscht : C:\Users\Benito\AppData\Roaming\Mozilla\Firefox\Profiles\q2h8cqw5.default\invalidprefs.js
Datei Gelöscht : C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\invalidprefs.js
Datei Gelöscht : C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\searchplugins\Babylon.xml
Datei Gelöscht : C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\searchplugins\delta.xml
Datei Gelöscht : C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\searchplugins\my-web-search.xml
Datei Gelöscht : C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\user.js
***** [ Geplante Tasks ] *****
Task Gelöscht : DigitalSite
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Updater]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKCU\Software\5d57dbd9b73be440
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550455185568}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660466186668}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{2FF49ED5-A3EF-410B-918E-97DECEB5996D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D48C9EAD-F59F-4DEA-AC97-7065FEA79F42}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{D48C9EAD-F59F-4DEA-AC97-7065FEA79F42}]
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{71C63272-91A7-436a-843D-A1C641D1C626}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9a216821-0ec5-49a3-85ac-fb72ae79a1e8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{71C63272-91A7-436a-843D-A1C641D1C626}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9a216821-0ec5-49a3-85ac-fb72ae79a1e8}
Schlüssel Gelöscht : HKCU\Software\BonanzaDealsLive
Schlüssel Gelöscht : HKCU\Software\dsiteproducts
Schlüssel Gelöscht : HKCU\Software\FromDocToPDF_65
Schlüssel Gelöscht : HKCU\Software\InstallCore
Schlüssel Gelöscht : HKCU\Software\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\FromDocToPDF_65
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Mediabarsh
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\TelevisionFanatic
Schlüssel Gelöscht : HKLM\SOFTWARE\FromDocToPDF_65
Schlüssel Gelöscht : HKLM\SOFTWARE\InstalledThirdPartyPrograms
Schlüssel Gelöscht : HKLM\SOFTWARE\Trymedia Systems
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{15D2D75C-9CB2-4EFD-BAD7-B9B4CB4BC693}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{E55B3271-7CA8-4D0C-AE06-69A24856E996}_is1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AVG Secure Search
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bonanza Deals
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta Chrome Toolbar
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Delta
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\DigitalSite
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyPC Backup
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\TelevisionFanaticbar Uninstall
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Whilokii
***** [ Internetbrowser ] *****
-\\ Internet Explorer v9.0.8112.16633
-\\ Mozilla Firefox v37.0.1 (x86 de)
[q2h8cqw5.default\prefs.js] - Zeile Gelöscht : user_pref("browser.newtab.url", "hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=6A500022FA1EA5E2&affID=119357&tt=240913_246&tsp=5019");
[q2h8cqw5.default\prefs.js] - Zeile Gelöscht : user_pref("browser.startup.homepage", "hxxp://www.searchgol.com/?babsrc=HP_ss&mntrId=6A500022FA1EA5E2&affID=119357&tt=240913_246&tsp=5019");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("browser.search.selectedEngine", "Delta Search");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.crossrider.bic", "142844f0c903b98c02adadfe77910329");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.admin", false);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.aflt", "babsst");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.autoRvrt", "false");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.dfltLng", "de");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.excTlbr", false);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.ffxUnstlRst", true);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.id", "6a5037810000000000000022fa1ea5e2");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.instlDay", "15976");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.instlRef", "sst");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.newTab", false);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.prdct", "delta");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.prtnrId", "delta");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.rvrt", "false");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.smplGrp", "none");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.tlbrId", "base");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.tlbrSrchUrl", "");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.vrsn", "1.8.24.6");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.vrsnTs", "1.8.24.622:41:14");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta.vrsni", "1.8.24.6");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta_i.babExt", "");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta_i.babTrack", "affID=119357&tt=240913_246&tsp=5019");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.delta_i.srcExt", "ss");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.dynconff.cache.dft.pathmapping.net.content", "<package expire=\"3600\" es=\"914\" pcdids=\"_1500_1520_1164_1524_1146_1169_1348_1482_1493_1521_1675\"><content id=\"us810_commonScr[...]
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.dynconff.cache.grooveshark.com.content", "<package expire=\"3600\" es=\"914\" pcdids=\"_1500_1520_1164_1524_1146_1169_1348_1482_1493_1521_1675\"><content id=\"us810_commonScript\[...]
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.dynconff.cache.www.northseasurfradio.com.content", "<package expire=\"3600\" es=\"914\" pcdids=\"_1500_1520_1164_1524_1146_1169_1348_1482_1493_1521_1675\"><content id=\"us810_com[...]
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mywebsearch.prevDefaultEngine", "");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.mywebsearch.prevSelectedEngine", "");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.homepage", "hxxp://home.mywebsearch.com/index.jhtml?ptb=DECFA255-C580-4620-87F2-7028890C9E35&n=77fd0a2e&p2=^Y6^xdm043^YY^de&si=swissconverter");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.hp.enabled", false);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.hp.lastGuardTime", 1970018210);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.hp.numGuards", 1);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.hp.user.defined", true);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.initialized", true);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.contextKey", "");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.installDate", "2013071918");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerId", "^Y6^xdm043^YY^de");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.partnerSubId", "swissconverter");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.success", true);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.installation.toolbarId", "DECFA255-C580-4620-87F2-7028890C9E35");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.lastActivePing", "1423851875318");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.defaultSearch", true);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.homePageEnabled", true);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.keywordEnabled", false);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.options.tabEnabled", false);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark._65Members_.weather.location", "10001");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark.hp.enabled", false);
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark.hp.enabled.guid", "");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("extensions.toolbar.mindspark.lastInstalled", "fromdoctopdf@mindspark.com");
[05orbz0y.default\prefs.js] - Zeile Gelöscht : user_pref("keyword.URL", "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?st=kwd&ptb=DECFA255-C580-4620-87F2-7028890C9E35&n=77fd0a2e&ind=2013071918&p2=^Y6^xdm043^YY^de&si=swissconverter&searchf[...]
-\\ Google Chrome v
*************************
AdwCleaner[R0].txt - [14037 Bytes] - [19/04/2015 16:16:21]
AdwCleaner[R1].txt - [13660 Bytes] - [19/04/2015 17:21:57]
AdwCleaner[S0].txt - [901 Bytes] - [19/04/2015 17:12:19]
AdwCleaner[S1].txt - [13976 Bytes] - [19/04/2015 17:27:47]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [14036 Bytes] ########## JRT-Log: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.8 (04.17.2015:1)
OS: Windows Vista (TM) Home Premium x86
Ran by srmdis on 19.04.2015 at 17:55:46,84
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Tasks
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440444184468}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440444184468}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E141F5C3-2619-4996-8AF8-AA0A9439D986}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E141F5C3-2619-4996-8AF8-AA0A9439D986}
~~~ Files
Successfully deleted: [File] C:\Windows\wininit.ini
~~~ Folders
Successfully deleted: [Folder] C:\Users\srmdis\AppData\Roaming\getrighttogo
Successfully deleted: [Folder] C:\Windows\system32\ai_recyclebin
~~~ FireFox
Emptied folder: C:\Users\srmdis\AppData\Roaming\mozilla\firefox\profiles\05orbz0y.default\minidumps [143 files]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 19.04.2015 at 18:00:55,58
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Aktueller FRST-Scan:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19-04-2015 01
Ran by srmdis (administrator) on MEINKLAPPTOP on 19-04-2015 18:10:15
Running from C:\Users\srmdis\Desktop
Loaded Profiles: srmdis (Available profiles: srmdis & Benito & Gast)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Google EULA Launcher] => c:\Program Files\Google\Google EULA\GoogleEULALauncher.exe [20480 2008-05-28] ( )
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1029416 2007-11-29] (Synaptics, Inc.)
HKLM\...\Run: [HDMICtrlMan] => C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [716800 2008-04-26] (TOSHIBA Corporation.)
HKLM\...\Run: [CanonSolutionMenu] => C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe [652624 2007-10-26] (CANON INC.)
HKLM\...\Run: [WPCUMI] => C:\Windows\system32\WpcUmi.exe [176128 2006-11-02] (Microsoft Corporation)
HKLM\...\Run: [NPSStartup] => [X]
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [41056 2013-05-08] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [BlueStacks Agent] => C:\Program Files\BlueStacks\HD-Agent.exe [601928 2013-07-04] (BlueStack Systems, Inc.)
HKLM\...\Run: [Camera Assistant Software] => C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe [417792 2008-04-29] (Chicony)
HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-07] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [Avira Systray] => C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\...\Run: [toscdspd] => TOSCDSPD.EXE
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\...\Run: [SmAudio] => C:\Program Files\Conexant\SmartAudio\SmAudio.exe [2712912 2008-10-29] (Conexant Systems, Inc.)
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\...\Policies\Explorer: [NoInstrumentation] 1
Startup: C:\Users\Anette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2009-11-03]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2008-07-10]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk [2008-07-10]
ShortcutTarget: TRDCReminder.lnk -> C:\Program Files\Toshiba\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
GroupPolicyUsers\S-1-5-21-4203143292-2018196265-3648757700-1004\User: Group Policy restriction detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
SearchScopes: HKLM -> {42D46B07-5919-4F66-9FBC-1B418FEE0FE5} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEA;
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4203143292-2018196265-3648757700-1000 -> ToolbarSearchProviderProgress {96bd48dd-741b-41ae-ac4a-aff96ba00f7e}
SearchScopes: HKU\S-1-5-21-4203143292-2018196265-3648757700-1000 -> {42D46B07-5919-4F66-9FBC-1B418FEE0FE5} URL = hxxp://www.google.com/search?source=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7GPEA_de
SearchScopes: HKU\S-1-5-21-4203143292-2018196265-3648757700-1000 -> {E52BE12D-A44A-4f51-9DC1-34F37A488CC7} URL = hxxp://search.videodownload-toolbar.com/search?p=Q&ts=ne&w={searchTerms}&csrc=search-field
BHO: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2013-05-08] (Adobe Systems Incorporated)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll [2015-02-23] (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22] (Microsoft Corporation)
BHO: Skype add-on for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08] (Skype Technologies S.A.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-02-23] (Oracle Corporation)
Toolbar: HKLM - PAYBACK Toolbar - {9613CB43-EA4C-48b5-878D-13DFE1818EFE} - C:\Program Files\Payback\PAYBACK Toolbar\PaybackToolbar.dll [2012-07-11] (PAYBACK GmbH)
Toolbar: HKLM - No Name - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No File
Toolbar: HKU\S-1-5-21-4203143292-2018196265-3648757700-1000 -> No Name - {E52BE12D-A44A-4F51-9DC1-34F37A488CC7} - No File
Toolbar: HKU\S-1-5-21-4203143292-2018196265-3648757700-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-4203143292-2018196265-3648757700-1000 -> PAYBACK Toolbar - {9613CB43-EA4C-48B5-878D-13DFE1818EFE} - C:\Program Files\Payback\PAYBACK Toolbar\PaybackToolbar.dll [2012-07-11] (PAYBACK GmbH)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-06-08] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll [2010-04-16] (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2010-02-08] (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies)
Tcpip\..\Interfaces\{944C3433-49ED-4329-B601-C11A37843AB3}: [NameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default
FF Homepage: https://www.google.de/
FF NetworkProxy: "share_proxy_settings", true
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-19] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1202122.dll [2013-04-26] (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-07-12] (Google)
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-02-23] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-02-23] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-30] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin: @zylom.com/ZylomGamesPlayer -> C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll No File
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-4203143292-2018196265-3648757700-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\srmdis\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-03-08] (Unity Technologies ApS)
FF Extension: Segurança do navegador Avira - C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\Extensions\abs@avira.com [2015-04-06]
FF Extension: FoxyProxy Standard - C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\Extensions\foxyproxy@eric.h.jung [2015-04-19]
FF Extension: Proxy-Listen.de - Proxyswitcher - C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\Extensions\admin@proxy-listen.de.xpi [2014-03-17]
FF Extension: Grooveshark Unlocker - C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-09-25]
FF Extension: SciLor's Grooveshark(tm) Unlocker for Germany - C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\Extensions\SciLorsGrooveUnlocker@scilor.com.xpi [2013-09-25]
FF Extension: PAYBACK Internet Assistent fuer Firefox - C:\Users\srmdis\AppData\Roaming\Mozilla\Firefox\Profiles\05orbz0y.default\Extensions\toolbar-ff@payback.de.xpi [2013-11-20]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-02-17]
FF HKU\S-1-5-21-4203143292-2018196265-3648757700-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
Chrome:
=======
CHR Profile: C:\Users\srmdis\AppData\Local\Google\Chrome\User Data\Default
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [icmlaeflemplmjndnaapfdbbnpncnbda] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx [Not Found]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [815352 2015-04-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [434424 2015-04-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-07] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1004032 2015-04-07] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [393032 2013-07-04] (BlueStack Systems, Inc.)
S2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [384840 2013-07-04] (BlueStack Systems, Inc.)
S2 ConfigFree Service; C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe [40960 2008-04-17] (TOSHIBA CORPORATION) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) [File not signed]
R2 FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [233472 2009-03-31] (Teruten) [File not signed]
S2 gupdate1c9ce8ca7271c73; C:\Program Files\Google\Update\GoogleUpdate.exe [107912 2014-10-24] (Google Inc.)
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S2 o2flash; C:\Program Files\O2Micro Flash Memory Card Driver\o2flash.exe [65536 2007-02-12] (O2Micro International) [File not signed]
S3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
S3 SmartFaceVWatchSrv; C:\Program Files\Toshiba\SmartFaceV\SmartFaceVWatchSrv.exe [73728 2008-04-24] (Toshiba) [File not signed]
S2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [116104 2009-04-21] (Toshiba Europe GmbH)
S2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-08-23] (Ulead Systems, Inc.) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [26032 2014-04-09] (Wondershare)
R1 aswKbd; C:\Windows\system32\Drivers\aswKbd.sys [24408 2012-03-07] (AVAST Software)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105864 2015-04-06] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2015-04-06] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2015-04-06] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [63816 2013-07-04] (BlueStack Systems)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [36608 2009-03-31] () [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-03-17] (Malwarebytes Corporation)
R3 QIOMem; C:\Windows\System32\DRIVERS\QIOMem.sys [8192 2007-04-09] (TOSHIBA)
R1 RrNetCapFilterDriver; C:\Windows\System32\DRIVERS\RrNetCapFilterDriver.sys [22184 2013-12-04] (Audials AG)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2015-04-06] (Avira GmbH)
R3 tbhsd; C:\Windows\System32\drivers\tbhsd.sys [39048 2013-12-04] (RapidSolution Software AG)
R3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [18432 2007-12-17] (Chicony Electronics Co., Ltd.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\srmdis\AppData\Local\Temp\catchme.sys [X]
S3 igfx; system32\DRIVERS\igdkmd32.sys [X]
S3 IntcHdmiAddService; system32\drivers\IntcHdmi.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 Tosrfcom; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-19 18:08 - 2015-04-19 18:09 - 00035184 ____C () C:\Users\srmdis\Desktop\Addition.txt
2015-04-19 18:07 - 2015-04-19 18:07 - 01137664 ____C (Farbar) C:\Users\srmdis\Desktop\FRST.exe
2015-04-19 18:04 - 2015-04-19 18:04 - 00000000 ___DC () C:\Users\srmdis\Desktop\FRST-OlderVersion
2015-04-19 18:00 - 2015-04-19 18:00 - 00001441 ____C () C:\Users\srmdis\Desktop\JRT.txt
2015-04-19 17:56 - 2015-04-19 17:56 - 00000207 ____C () C:\Windows\tweaking.com-regbackup-MEINKLAPPTOP-Windows-Vista-(TM)-Home-Premium-(32-bit).dat
2015-04-19 17:55 - 2015-04-19 17:55 - 00000000 ___DC () C:\RegBackup
2015-04-19 17:54 - 2015-04-19 17:54 - 02686254 ____C (Thisisu) C:\Users\srmdis\Desktop\JRT.exe
2015-04-19 17:19 - 2015-04-19 17:19 - 02217984 ____C () C:\Users\srmdis\Downloads\AdwCleaner_4.201(1).exe
2015-04-19 16:16 - 2015-04-19 17:28 - 00000000 ___DC () C:\AdwCleaner
2015-04-19 16:15 - 2015-04-19 16:15 - 02217984 ____C () C:\Users\srmdis\Downloads\AdwCleaner_4.201.exe
2015-04-19 16:04 - 2015-04-19 16:04 - 00011718 ____C () C:\Malwarebytes Suchlauf 01.txt
2015-04-19 15:18 - 2015-04-19 15:19 - 00119512 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-19 15:18 - 2015-04-19 15:18 - 00000904 ____C () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-19 15:17 - 2015-04-19 15:18 - 00000000 ___DC () C:\Program Files\Malwarebytes Anti-Malware
2015-04-19 15:17 - 2015-04-19 15:17 - 00000000 ___DC () C:\ProgramData\Malwarebytes
2015-04-19 15:17 - 2015-03-17 06:15 - 00092888 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-04-19 15:17 - 2015-03-17 06:15 - 00051928 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-04-19 15:17 - 2015-03-17 06:15 - 00023256 ____C (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-04-19 15:14 - 2015-04-19 15:15 - 21540440 ____C (Malwarebytes Corporation ) C:\Users\srmdis\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-11 11:05 - 2015-04-11 11:05 - 00000000 ___DC () C:\ProgramData\Package Cache
2015-04-08 15:50 - 2015-04-08 15:51 - 00000000 __SDC () C:\ComboFix
2015-04-08 12:18 - 2011-06-26 08:45 - 00256000 ____C () C:\Windows\PEV.exe
2015-04-08 12:18 - 2010-11-07 19:20 - 00208896 ____C () C:\Windows\MBR.exe
2015-04-08 12:18 - 2009-04-20 06:56 - 00060416 ____C (NirSoft) C:\Windows\NIRCMD.exe
2015-04-08 12:18 - 2000-08-31 02:00 - 00518144 ____C (SteelWerX) C:\Windows\SWREG.exe
2015-04-08 12:18 - 2000-08-31 02:00 - 00406528 ____C (SteelWerX) C:\Windows\SWSC.exe
2015-04-08 12:18 - 2000-08-31 02:00 - 00098816 ____C () C:\Windows\sed.exe
2015-04-08 12:18 - 2000-08-31 02:00 - 00080412 ____C () C:\Windows\grep.exe
2015-04-08 12:18 - 2000-08-31 02:00 - 00068096 ____C () C:\Windows\zip.exe
2015-04-08 12:16 - 2015-04-08 12:18 - 00000000 ___DC () C:\Qoobox
2015-04-08 12:15 - 2015-04-08 12:15 - 00000000 ___DC () C:\Windows\erdnt
2015-04-08 12:14 - 2015-04-08 15:50 - 00000000 __SDC () C:\32788R22FWJFW
2015-04-08 12:13 - 2015-04-08 12:14 - 05617096 ___RC (Swearware) C:\Users\srmdis\Desktop\ComboFix.exe
2015-04-08 11:49 - 2012-09-23 22:35 - 00699536 ____C (MindSpark) C:\Program Files\64Uninstall TelevisionFanatic.dll
2015-04-08 11:49 - 2012-09-23 22:35 - 00172456 ____C () C:\Program Files\64res.dll
2015-04-08 11:15 - 2015-04-08 11:15 - 00001080 ____C () C:\Users\srmdis\Desktop\Revo Uninstaller.lnk
2015-04-08 11:15 - 2015-04-08 11:15 - 00000000 ___DC () C:\Program Files\VS Revo Group
2015-04-08 11:13 - 2015-04-08 11:13 - 02623656 ____C (VS Revo Group Ltd.) C:\Users\srmdis\Downloads\revosetup95.exe
2015-04-07 10:42 - 2015-04-19 18:10 - 00018686 ____C () C:\Users\srmdis\Desktop\FRST.txt
2015-04-07 10:42 - 2015-04-19 18:10 - 00000000 ___DC () C:\FRST
2015-04-06 16:48 - 2015-04-06 16:48 - 00000937 ____C () C:\Users\srmdis\Desktop\esetsmartinstaller_deu - Verknüpfung.lnk
2015-04-06 16:48 - 2015-04-06 16:48 - 00000000 ___DC () C:\Program Files\ESET
2015-04-06 16:47 - 2015-04-06 16:47 - 02347384 ____C (ESET) C:\Users\srmdis\Downloads\esetsmartinstaller_deu.exe
2015-04-06 16:28 - 2015-04-06 16:28 - 00243656 ____C () C:\Users\srmdis\Downloads\Firefox Setup Stub 37.0.1.exe
2015-04-06 16:00 - 2015-04-06 16:02 - 24301976 ____C () C:\Users\srmdis\Downloads\driver_audio_conexant_TC70050000A(1).exe
2015-04-06 16:00 - 2015-04-06 16:01 - 24301976 ____C () C:\Users\srmdis\Downloads\driver_audio_conexant_TC70050000A.exe
2015-04-06 15:21 - 2015-04-07 14:38 - 00000000 ___DC () C:\Users\srmdis\AppData\Roaming\Avira
2015-04-06 15:17 - 2015-04-06 15:10 - 00136216 ____C (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-04-06 15:17 - 2015-04-06 15:10 - 00105864 ____C (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-04-06 15:17 - 2015-04-06 15:10 - 00037352 ____C (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-04-06 15:17 - 2015-04-06 15:10 - 00028520 ____C (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2015-04-06 14:37 - 2015-04-19 17:30 - 00174298 ____C () C:\Windows\PFRO.log
2015-04-06 14:16 - 2015-04-06 14:16 - 00000918 ____C () C:\Users\srmdis\Documents\cc_20150406_141643.reg
2015-03-28 17:10 - 2015-04-08 15:34 - 00000000 ___DC () C:\Program Files\Mozilla Firefox
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-19 18:10 - 2009-02-12 13:02 - 00000418 ___HC () C:\Windows\Tasks\User_Feed_Synchronization-{1D6C683A-5F44-44BD-A493-C7E113AD41AA}.job
2015-04-19 17:58 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-19 17:58 - 2006-11-02 14:47 - 00003216 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-19 17:37 - 2008-01-21 09:16 - 01565124 ____C () C:\Windows\system32\PerfStringBackup.INI
2015-04-19 17:36 - 2009-06-30 19:34 - 00001060 ____C () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-19 17:35 - 2010-01-24 21:53 - 01541719 ____C () C:\Windows\WindowsUpdate.log
2015-04-19 17:33 - 2013-05-31 22:29 - 00000350 ____C () C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2015-04-19 17:33 - 2009-06-30 19:34 - 00001056 ____C () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-19 17:30 - 2012-04-03 21:01 - 00000884 ____C () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-19 17:30 - 2006-11-02 15:01 - 00000006 ___HC () C:\Windows\Tasks\SA.DAT
2015-04-19 17:29 - 2006-11-02 15:01 - 00032606 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-04-19 15:29 - 2012-04-03 21:01 - 00778416 ____C (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-04-19 15:29 - 2011-05-17 09:42 - 00142512 ____C (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-04-11 11:06 - 2013-03-19 22:37 - 00000000 ___DC () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-11 11:06 - 2013-03-19 22:37 - 00000000 ___DC () C:\Program Files\Avira
2015-04-08 15:34 - 2013-06-17 18:18 - 00000000 ___DC () C:\Program Files\OXXOGames
2015-04-08 15:34 - 2012-10-13 12:59 - 00000000 ___DC () C:\Program Files\Mozilla Maintenance Service
2015-04-08 12:37 - 2009-02-06 15:41 - 00000000 ___DC () C:\Users\srmdis
2015-04-08 11:31 - 2011-04-15 20:17 - 00000000 ___DC () C:\Program Files\Shareaza Applications
2015-04-07 17:58 - 2006-11-02 14:37 - 00000000 __RDC () C:\Users\srmdis\Desktop\Games
2015-04-07 14:36 - 2013-03-19 22:37 - 00000000 ___DC () C:\ProgramData\Avira
2015-04-06 16:31 - 2012-02-05 18:50 - 00000869 ____C () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-04-06 16:31 - 2012-02-05 18:23 - 00000857 ____C () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-04-06 15:14 - 2013-07-19 18:21 - 00000000 ___DC () C:\Users\srmdis\AppData\Roaming\.minecraft
2015-04-04 12:56 - 2010-08-15 15:01 - 00000680 ____C () C:\Users\srmdis\AppData\Local\d3d9caps.dat
==================== Files in the root of some directories =======
2015-04-08 11:49 - 2012-09-23 22:35 - 0172456 ____C () C:\Program Files\64res.dll
2015-04-08 11:49 - 2012-09-23 22:35 - 0699536 ____C (MindSpark) C:\Program Files\64Uninstall TelevisionFanatic.dll
2015-02-13 20:42 - 2013-05-20 15:40 - 0186752 ____C () C:\Program Files\65res.dll
2015-02-13 20:42 - 2013-05-20 15:40 - 0708168 ____C (MindSpark) C:\Program Files\65Uninstall FromDocToPDF.dll
2014-12-24 23:31 - 2014-12-24 23:39 - 0000369 ____C () C:\Users\srmdis\AppData\Roaming\.foobillardrc
2009-02-07 12:46 - 2009-02-07 12:46 - 0000016 ___HC () C:\Users\srmdis\AppData\Roaming\mxfilerelatedcache.mxc2
2009-11-07 21:59 - 2009-11-07 21:59 - 0025903 ____C () C:\Users\srmdis\AppData\Roaming\UserTile.png
2013-09-29 11:40 - 2014-10-21 16:38 - 0000093 ____C () C:\Users\srmdis\AppData\Roaming\WB.CFG
2013-09-29 11:40 - 2014-02-01 01:40 - 0000005 ____C () C:\Users\srmdis\AppData\Roaming\WBPU-TTL.DAT
2009-02-07 14:28 - 2015-02-22 18:22 - 0005558 ____C () C:\Users\srmdis\AppData\Roaming\wklnhst.dat
2010-08-15 15:01 - 2015-04-04 12:56 - 0000680 ____C () C:\Users\srmdis\AppData\Local\d3d9caps.dat
2009-12-05 23:47 - 2014-12-25 14:40 - 0045568 ____C () C:\Users\srmdis\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2009-12-13 21:41 - 2009-12-13 21:41 - 0000016 ___HC () C:\Users\srmdis\AppData\Local\mxfilerelatedcache.mxc2
2014-06-10 18:55 - 2014-06-10 18:55 - 0000000 ____C () C:\Users\srmdis\AppData\Local\{46F898B1-04B3-4243-8B9E-0BDD44F8C4CA}
2009-11-20 21:44 - 2009-11-20 21:44 - 0000016 ___HC () C:\ProgramData\mxfilerelatedcache.mxc2
Some content of TEMP:
====================
C:\Users\srmdis\AppData\Local\Temp\avgnt.exe
C:\Users\srmdis\AppData\Local\Temp\Quarantine.exe
C:\Users\srmdis\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-19 17:38
==================== End Of Log ============================ --- --- ---
--- --- --- |