![]() |
Laptop anscheinden von Viren oder Trojaner befallen Liste der Anhänge anzeigen (Anzahl: 2) Hallo liebe Forum-Mitglieder, mein Laptop ist seit Tagen sehr langsam, nun fährt er auch nicht mehr runter und geht nicht in den Standby-Modus. Sowohl das Ausführen von Befehlen als auch Surfen im Internet ist sehr langsam. Das System hängt sich öfters auf. Logfiles sind im Anhang. Vielen Dank im Voraus! Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01 Ran by Com (administrator) on USER (25-08-2016 14:06:12) Running from C:\Users\Com\Downloads Loaded Profiles: Com (Available Profiles: Com) Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Atheros Commnucations) C:\Windows\System32\AdminService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avp.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avpui.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Intel® Corporation) C:\Program Files\Intel\ConnectCenter\bin\CCFManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Intel Corporation) C:\Program Files\Intel\STCServ\STCServ.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusSmartGestureDetector64.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusSGPlusBTServer64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\scalc.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\WINWORD.EXE (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated) HKLM\...\Run: [IntelConnectCenter] => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [90112 2015-03-16] (Intel® Corporation) HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [247016 2011-09-09] (CyberLink Corp.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [74752 2015-09-02] () HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [204560 2016-08-18] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [226816 2016-05-23] (Geek Software GmbH) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [67864 2016-08-04] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [831576 2016-08-25] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.) HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23375200 2016-07-29] (Google) HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Policies\Explorer: [NoDrives] 0x00000000 IFEO\uninst.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{C79A7648-F485-45BF-BE3C-29E6202DDFA5}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{FD466CB9-31B0-4EA9-8877-1A184043BC69}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKU\S-1-5-21-245667631-3740917297-2571881347-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKU\S-1-5-21-245667631-3740917297-2571881347-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-245667631-3740917297-2571881347-1001 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = SearchScopes: HKU\S-1-5-21-245667631-3740917297-2571881347-1001 -> {24E0BF82-5E77-4A8A-A1C7-1F5BCD37122E} URL = SearchScopes: HKU\S-1-5-21-245667631-3740917297-2571881347-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Kaspersky Protection -> {03993315-5CE9-4F00-8790-D14A94F1D91A} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\x64\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-02-09] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-02-09] (Microsoft Corporation) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2014-12-15] (DVDVideoSoft Ltd.) BHO-x32: Kaspersky Protection -> {03993315-5CE9-4F00-8790-D14A94F1D91A} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-02-09] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-04-09] (Oracle Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2016-02-09] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-09] (Oracle Corporation) BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2014-12-15] (DVDVideoSoft Ltd.) Toolbar: HKLM - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\x64\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) FireFox: ======== FF ProfilePath: C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default FF NetworkProxy: "ftp", "80.77.29.22" FF NetworkProxy: "ftp_port", 80 FF NetworkProxy: "http", "80.77.29.22" FF NetworkProxy: "http_port", 80 FF NetworkProxy: "socks", "80.77.29.22" FF NetworkProxy: "socks_port", 80 FF NetworkProxy: "ssl", "80.77.29.22" FF NetworkProxy: "ssl_port", 80 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] () FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-09] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-09] (Oracle Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-18] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-04-01] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems) FF user.js: detected! => C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\user.js [2016-03-27] FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-11-18] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-06-23] (Adobe Systems Inc.) FF Extension: Avira Browser Safety - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\abs@avira.com [2016-08-19] FF Extension: German Dictionary - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2016-08-16] FF Extension: Diccionario Español Argentina - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\es-AR@dictionaries.addons.mozilla.org [2016-04-06] [not signed] FF Extension: One Click Proxy - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\jid0-zXo3XFGyiDalgkeEO4UYJTUwo2I@jetpack.xpi [2016-04-19] FF Extension: Avira SafeSearch Plus - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\safesearchplus2@avira.com [2016-08-19] FF Extension: Adblock Plus - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2014-12-15] [not signed] FF HKLM-x32\...\Firefox\Extensions: [light_plugin_ACF0E80077C511E59DED005056C00008@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\FFExt\light_plugin_firefox\addon.xpi FF Extension: Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\FFExt\light_plugin_firefox\addon.xpi [2016-08-20] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found FF HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-12-24] [not signed] Chrome: ======= CHR DefaultSearchURL: Profile 2 -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms} CHR DefaultSearchKeyword: Profile 2 -> Avira CHR DefaultSuggestURL: Profile 2 -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en CHR Profile: C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-17] CHR Extension: (Google Docs) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-17] CHR Extension: (Google Drive) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-17] CHR Extension: (YouTube) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-17] CHR Extension: (Google Sheets) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-17] CHR Extension: (Google Docs Offline) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-18] CHR Extension: (Chrome Web Store Payments) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-17] CHR Extension: (Gmail) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-17] CHR Profile: C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Slides) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-26] CHR Extension: (Google Docs) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-26] CHR Extension: (Google Drive) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-26] CHR Extension: (YouTube) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-26] CHR Extension: (Google Sheets) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-26] CHR Extension: (Google Docs Offline) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-26] CHR Extension: (Chrome Web Store Payments) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-26] CHR Extension: (Gmail) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-26] CHR Profile: C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2 CHR Extension: (Google Slides) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-26] CHR Extension: (Google Docs) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-26] CHR Extension: (Google Drive) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-26] CHR Extension: (YouTube) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-26] CHR Extension: (Google Sheets) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-26] CHR Extension: (Avira Browser Safety) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-08-20] CHR Extension: (Google Docs Offline) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-27] CHR Extension: (Avira SafeSearch Plus) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2016-08-20] CHR Extension: (Kaspersky Protection) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lpeeaghdjmhlakojjcgfdhgcejdaefmi [2016-08-20] CHR Extension: (Chrome Web Store Payments) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-26] CHR Extension: (Gmail) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-26] CHR Extension: (Chrome Media Router) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-20] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2159320 2016-08-22] (Adobe Systems, Incorporated) S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [988184 2016-08-25] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [470600 2016-08-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [470600 2016-08-25] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1453696 2016-08-25] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Windows\system32\AdminService.exe [208384 2012-08-29] (Atheros Commnucations) [File not signed] R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1097488 2016-08-18] (AVG Technologies CZ, s.r.o.) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [320672 2016-08-04] (Avira Operations GmbH & Co. KG) R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [234352 2016-07-29] (Avira Operations GmbH & Co. KG) R2 AVP16.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avp.exe [236928 2015-12-22] (AO Kaspersky Lab) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2015-09-02] (Freemake) [File not signed] S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\x64\vssbridge64.exe [152488 2015-12-22] (AO Kaspersky Lab) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 STCServ; C:\Program Files\Intel\STCServ\STCServ.exe [8095456 2015-03-16] (Intel Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7032080 2016-05-12] (TeamViewer GmbH) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [4878096 2016-08-19] (AVG Technologies CZ, s.r.o.) S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-10-29] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3855872 2013-09-25] (Qualcomm Atheros Communications, Inc.) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [69904 2015-10-07] (ASUS Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [144664 2016-07-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [154392 2016-07-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [35488 2016-07-18] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [78208 2016-07-18] (Avira Operations GmbH & Co. KG) R3 bcmsmbsp; C:\Windows\System32\drivers\bcmsmbsp.sys [40152 2013-09-09] (Broadcom Corporation.) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO) S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-03-04] () R3 GPIO; C:\Windows\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation) R3 iaioi2c; C:\Windows\System32\drivers\iaioi2ce.sys [67584 2013-11-11] (Intel Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-09-11] (Kaspersky Lab ZAO) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [79752 2015-12-01] (AO Kaspersky Lab) R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [78200 2015-12-02] (AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [30328 2015-06-24] (Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [182664 2015-12-11] (AO Kaspersky Lab) R1 klhk; C:\Windows\System32\drivers\klhk.sys [237400 2016-08-20] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [992600 2016-08-20] (AO Kaspersky Lab) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [51288 2016-04-29] (AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [52608 2015-11-11] (AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45960 2015-12-07] (AO Kaspersky Lab) S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [87984 2016-08-20] (AO Kaspersky Lab) R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [110424 2016-08-20] (AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [194440 2015-12-03] (AO Kaspersky Lab) S3 massfilter; C:\Windows\System32\drivers\ztembbmassfilter.sys [15360 2012-11-23] (MBB Incorporated) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-08-25] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-11] (Intel Corporation) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.) S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr)) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-03-29] (AVG Netherlands B.V.) R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2013-10-31] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [236888 2013-10-31] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation) S3 WUDFWpdComp; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation) S3 ZTEusbmdm6k; C:\Windows\system32\DRIVERS\ztembbusbmdm.sys [123264 2012-11-23] (ZTE Incorporated) S3 ZTEusbnmea; C:\Windows\system32\DRIVERS\ztembbusbnmea.sys [123264 2012-11-23] (ZTE Incorporated) S3 ZTEusbser6K; C:\Windows\system32\DRIVERS\ztembbusbser6k.sys [123264 2012-11-23] (ZTE Incorporated) S3 ZTEusbvoice; C:\Windows\system32\DRIVERS\ztembbusbvoice.sys [123264 2012-11-23] (ZTE Incorporated) U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X] S4 nvlddmkm; \SystemRoot\system32\DRIVERS\nvlddmkm.sys [X] S4 nvpciflt; \SystemRoot\system32\DRIVERS\nvpciflt.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-25 14:06 - 2016-08-25 14:07 - 00028883 _____ C:\Users\Com\Downloads\FRST.txt 2016-08-25 14:05 - 2016-08-25 14:06 - 00000000 ____D C:\FRST 2016-08-25 14:05 - 2016-08-25 14:05 - 02396672 _____ (Farbar) C:\Users\Com\Downloads\FRST64.exe 2016-08-25 13:23 - 2016-08-25 13:23 - 00000091 ____H C:\Users\Com\Desktop\.~lock.cv roman.doc# 2016-08-25 12:53 - 2016-08-25 12:53 - 00411216 _____ C:\Users\Com\Downloads\ceo_resume_template.pdf 2016-08-25 12:52 - 2016-08-25 12:52 - 00169358 _____ C:\Users\Com\Desktop\sample-CEO-resume.pdf 2016-08-25 12:51 - 2016-08-25 12:51 - 00178626 _____ C:\Users\Com\Downloads\sample-CEO-resume.pdf 2016-08-25 12:30 - 2016-08-25 12:30 - 00012362 _____ C:\Users\Com\Downloads\Sample CV in English.pdf 2016-08-24 16:31 - 2016-08-25 13:14 - 00019186 _____ C:\Users\Com\Desktop\cv roman.odt 2016-08-24 14:45 - 2016-08-24 14:45 - 00096514 _____ C:\Users\Com\Downloads\dfg_initiativ_2012.pdf 2016-08-23 20:43 - 2016-08-23 20:43 - 00154656 _____ C:\Users\Com\Downloads\fb03-0010-frsek-260816(1).pdf 2016-08-23 20:40 - 2016-08-23 20:40 - 00154656 _____ C:\Users\Com\Downloads\fb03-0010-frsek-260816.pdf 2016-08-23 09:33 - 2016-08-25 09:54 - 00001537 _____ C:\Users\Com\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AsusSmartGestureDetector.lnk 2016-08-20 22:30 - 2016-08-20 22:30 - 30166566 _____ C:\Users\Com\Downloads\DSCN1595.MOV 2016-08-20 20:15 - 2016-08-20 20:16 - 91467869 _____ C:\Users\Com\Downloads\DSCN1568.MOV 2016-08-20 20:11 - 2016-08-20 20:11 - 37532381 _____ C:\Users\Com\Downloads\DSCN1547.MOV 2016-08-20 20:10 - 2016-08-20 20:11 - 48410081 _____ C:\Users\Com\Downloads\DSCN1546.MOV 2016-08-20 19:07 - 2016-08-20 19:07 - 21830775 _____ C:\Users\Com\Downloads\DSCN1600.MOV 2016-08-20 19:07 - 2016-08-20 19:07 - 10102483 _____ C:\Users\Com\Downloads\DSCN1553.MOV 2016-08-20 19:06 - 2016-08-20 19:07 - 17810256 _____ C:\Users\Com\Downloads\DSCN1599.MOV 2016-08-20 19:06 - 2016-08-20 19:06 - 11296539 _____ C:\Users\Com\Downloads\DSCN1598.MOV 2016-08-20 19:04 - 2016-08-20 19:04 - 21394464 _____ C:\Users\Com\Downloads\DSCN1597.MOV 2016-08-20 19:03 - 2016-08-20 19:03 - 16439466 _____ C:\Users\Com\Downloads\DSCN1596.MOV 2016-08-20 18:59 - 2016-08-20 19:00 - 48668490 _____ C:\Users\Com\Downloads\DSCN1602.MOV 2016-08-20 14:51 - 2016-08-21 11:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\47F665AA.sys 2016-08-20 14:35 - 2016-08-20 14:35 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\4F505988.sys 2016-08-20 01:04 - 2016-08-20 01:04 - 00002107 _____ C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2016-08-20 01:04 - 2016-08-20 01:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2016-08-20 01:03 - 2016-08-25 12:09 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2016-08-20 01:03 - 2016-08-20 01:03 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2016-08-20 01:03 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2016-08-20 01:02 - 2016-08-20 12:32 - 00992600 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2016-08-20 01:02 - 2015-12-11 17:31 - 00182664 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2016-08-20 00:47 - 2016-08-20 00:47 - 01932640 _____ (Kaspersky Lab) C:\Users\Com\Downloads\kav16.0.0.614abcdde_9831.exe 2016-08-20 00:06 - 2016-08-20 00:06 - 02041880 _____ (Kaspersky Lab) C:\Users\Com\Downloads\kav16.0.1.445abcde_10532.exe 2016-08-19 23:50 - 2016-08-19 23:50 - 03143504 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Com\Downloads\AVG_Protection_Free_1606.exe 2016-08-19 23:44 - 2016-08-19 23:44 - 00001068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira Phantom VPN.lnk 2016-08-19 23:44 - 2016-08-19 23:44 - 00001056 _____ C:\Users\Public\Desktop\Avira Phantom VPN.lnk 2016-08-19 23:44 - 2016-08-19 23:44 - 00000000 ____D C:\Users\Com\AppData\Roaming\Avira 2016-08-19 23:40 - 2016-07-18 16:23 - 00154392 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2016-08-19 23:40 - 2016-07-18 16:23 - 00144664 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2016-08-19 23:40 - 2016-07-18 16:23 - 00078208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2016-08-19 23:40 - 2016-07-18 16:23 - 00035488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2016-08-19 23:38 - 2016-08-19 23:38 - 04831216 _____ (Avira Operations GmbH & Co. KG) C:\Users\Com\Downloads\avira_en_av_57b77bc3aa496__ws(1).exe 2016-08-19 23:37 - 2016-08-25 10:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2016-08-19 23:37 - 2016-08-19 23:37 - 00001222 _____ C:\Users\Public\Desktop\Avira Launcher.lnk 2016-08-19 23:36 - 2016-08-19 23:36 - 04831216 _____ (Avira Operations GmbH & Co. KG) C:\Users\Com\Downloads\avira_en_av_57b77bc3aa496__ws.exe 2016-08-19 23:25 - 2016-08-25 13:44 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-08-19 23:25 - 2016-08-19 23:25 - 00001114 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-08-19 23:25 - 2016-08-19 23:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-08-19 23:25 - 2016-08-19 23:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-08-19 23:25 - 2016-08-19 23:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-08-19 23:25 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-08-19 23:25 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-08-19 23:25 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-08-19 23:24 - 2016-08-19 23:24 - 22851472 _____ (Malwarebytes ) C:\Users\Com\Downloads\mbam-setup-2.2.1.1043.exe 2016-08-19 18:13 - 2016-08-19 18:13 - 00074187 _____ C:\Users\Com\Downloads\ma_polwis_zugangssatzung.pdf 2016-08-18 21:56 - 2016-08-19 23:25 - 00025156 _____ C:\Users\Com\Desktop\Untitled 1.odt 2016-08-18 20:09 - 2016-08-18 20:09 - 00028158 _____ C:\Users\Com\Downloads\Anlage(1).pdf 2016-08-18 19:48 - 2016-08-18 19:48 - 03746280 _____ C:\Users\Com\Downloads\broschuere-berufsbilder-im-sprachendienst-11-data.pdf 2016-08-16 21:06 - 2016-08-16 21:06 - 00014239 _____ C:\Users\Com\Documents\Untitled 1.odt 2016-08-16 18:28 - 2016-08-16 18:28 - 02397951 _____ C:\Users\Com\Downloads\Veranstaltungsprogramm und Anmeldeformular.als PDF.pdf 2016-08-12 13:15 - 2016-08-12 13:15 - 04014191 _____ C:\Users\Com\Desktop\Bewerbungsmappe_V.Stanislavski_AA Frankfurt.pdf 2016-08-12 12:11 - 2016-08-12 12:18 - 00058981 _____ C:\Users\Com\Desktop\Nachweis Eigenbemühungen V.Stanislavski.pdf 2016-08-12 12:07 - 2016-08-12 12:07 - 00061012 _____ C:\Users\Com\Documents\Nachweis Eigenbemühungen V.Stanislavski.pdf 2016-08-10 21:08 - 2016-08-10 21:08 - 00023214 _____ C:\Users\Com\Documents\AA.odt 2016-08-09 14:49 - 2016-08-09 14:49 - 00129474 _____ C:\Users\Com\Downloads\egov-content438289.pdf 2016-08-09 14:47 - 2016-08-09 14:47 - 00143605 _____ C:\Users\Com\Downloads\l6019022dstbai808947.pdf 2016-08-09 14:32 - 2016-08-09 14:32 - 00676466 _____ C:\Users\Com\Downloads\eb-sgbiii-443-0-pdf.pdf 2016-08-09 12:37 - 2016-08-09 12:37 - 02468086 _____ C:\Users\Com\Downloads\Sfs_Studie.pdf 2016-08-09 01:14 - 2016-08-09 01:14 - 00053785 _____ C:\Users\Com\Downloads\data.pdf 2016-08-09 00:33 - 2016-08-09 00:33 - 08793295 _____ C:\Users\Com\Downloads\6019022dstbai386915.pdf 2016-08-08 14:11 - 2016-08-08 14:11 - 00082002 _____ C:\Users\Com\Downloads\tvoed-bund(1).pdf 2016-08-08 11:58 - 2016-08-08 11:58 - 10046619 _____ C:\Users\Com\Downloads\l6019022dstbai665890.pdf 2016-08-08 07:13 - 2016-08-08 07:13 - 00049485 _____ C:\Users\Com\Documents\Test_translation_2_V.Stanislavski.pdf 2016-08-08 07:13 - 2016-08-08 07:13 - 00048708 _____ C:\Users\Com\Documents\Test_translation_1_V.Stanislavski.pdf 2016-08-06 19:22 - 2016-08-06 19:22 - 04498815 _____ C:\Users\Com\Downloads\Weissbuch2016_barrierefrei.pdf 2016-08-06 19:22 - 2016-08-06 19:22 - 04498815 _____ C:\Users\Com\Downloads\Weissbuch2016_barrierefrei(1).pdf 2016-08-06 18:58 - 2016-08-06 18:58 - 00016473 _____ C:\Users\Com\Downloads\Auswahlverfahren.pdf 2016-08-05 12:44 - 2016-08-05 12:45 - 04235939 _____ C:\Users\Com\Downloads\tpi125_de_en.pdf 2016-08-03 13:44 - 2016-08-03 13:44 - 00121863 _____ C:\Users\Com\Downloads\Form(4).pdf 2016-08-03 13:43 - 2016-08-03 13:43 - 00059748 _____ C:\Users\Com\Downloads\Registrierungsbestätigung.PDF 2016-08-03 13:42 - 2016-08-03 13:42 - 00121863 _____ C:\Users\Com\Downloads\Form(3).pdf 2016-08-03 13:42 - 2016-08-03 13:42 - 00121863 _____ C:\Users\Com\Downloads\Form(2).pdf 2016-08-03 13:41 - 2016-08-03 13:42 - 00122956 _____ C:\Users\Com\Downloads\Form(1).pdf 2016-08-03 13:41 - 2016-08-03 13:41 - 00122956 _____ C:\Users\Com\Downloads\Form.pdf 2016-08-03 12:15 - 2016-08-03 12:15 - 00082002 _____ C:\Users\Com\Downloads\tvoed-bund.pdf 2016-08-02 22:17 - 2016-08-02 22:17 - 00390997 _____ C:\Users\Com\Downloads\UdOe30.pdf 2016-08-01 17:03 - 2016-08-17 00:34 - 00082071 _____ C:\Users\Com\Documents\Übersetzung.odt 2016-08-01 14:29 - 2016-08-01 14:29 - 00339808 _____ C:\Users\Com\Downloads\TOEFL_V.Stanislavski.pdf 2016-07-30 16:55 - 2016-07-30 16:55 - 02172833 _____ C:\Users\Com\Downloads\Arbeitszeugnisse_V.Stanislavski.pdf 2016-07-30 13:17 - 2016-07-30 13:17 - 00118450 _____ C:\Users\Com\Downloads\Merkblatt_SA_in_der_UA_Web_2015-1611.pdf 2016-07-29 12:28 - 2016-07-29 12:28 - 00388067 _____ C:\Users\Com\Downloads\Daten#bersicht 2016-07-29 12:15 - 2016-07-29 12:15 - 02263569 _____ C:\Users\Com\Downloads\160722_Stellenanzeige_Projektmanager_Bremen.pdf 2016-07-29 11:33 - 2016-07-29 11:33 - 01746479 _____ C:\Users\Com\Documents\Bildungszeugnisse_V.Stanislavski.pdf 2016-07-29 11:32 - 2016-07-29 11:32 - 01038107 _____ C:\Users\Com\Documents\Arbeitszeugnisse_V.Stanislavski.pdf 2016-07-29 10:02 - 2016-08-22 21:39 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1e96f7ed57473.job 2016-07-29 10:02 - 2016-08-22 21:39 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-07-29 10:02 - 2016-08-21 13:22 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d1e96f7ed57473 2016-07-29 10:02 - 2016-08-21 13:22 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-07-28 18:10 - 2016-07-28 18:10 - 07422017 _____ C:\Users\Com\Downloads\Bewerbung.pdf 2016-07-28 17:44 - 2016-07-28 17:44 - 07263884 _____ C:\Users\Com\Downloads\Bewerbungsprofil.pdf 2016-07-28 16:35 - 2016-07-28 16:35 - 00840274 _____ C:\Users\Com\Documents\Zeugnisse_V. Stanislavski.pdf 2016-07-28 15:42 - 2016-07-28 15:42 - 00196363 _____ C:\Users\Com\Downloads\2016-06-25_Praktikum_Intendanz_IFB.pdf 2016-07-27 18:43 - 2016-07-27 18:43 - 00088179 _____ C:\Users\Com\Downloads\20160706_Ausschreibung F 44.pdf 2016-07-26 16:58 - 2016-07-26 16:58 - 00925992 _____ C:\Users\Com\Downloads\uepo_300_2010_2013-09-22.pdf 2016-07-26 16:31 - 2016-07-26 16:31 - 05987736 _____ C:\Users\Com\Downloads\infoNRW_1_2014_online.pdf 2016-07-26 15:52 - 2016-07-26 18:34 - 00013568 _____ C:\Users\Com\Documents\Kalkulation_Matrix.ods 2016-07-26 12:05 - 2016-07-26 12:27 - 00968071 _____ C:\Users\Com\Documents\Bewerbungsmappe_V.Stanislavski_AfA_Montabaur.pdf ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-25 14:04 - 2014-02-17 04:18 - 00000000 ____D C:\Users\Com\AppData\Roaming\Skype 2016-08-25 13:58 - 2016-04-10 12:05 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-08-25 13:26 - 2014-12-29 17:06 - 06140928 ___SH C:\Users\Com\Desktop\Thumbs.db 2016-08-25 13:22 - 2014-12-17 09:00 - 07687168 ___SH C:\Users\Com\Downloads\Thumbs.db 2016-08-25 11:58 - 2014-02-16 13:45 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-245667631-3740917297-2571881347-1001 2016-08-25 11:58 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf 2016-08-25 09:59 - 2014-02-17 04:36 - 00000000 ____D C:\Users\Com\AppData\Local\Adobe 2016-08-25 09:58 - 2014-12-16 17:22 - 00003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{73BFAA1B-1E35-478D-B893-0170BDE89573} 2016-08-25 09:56 - 2014-02-16 13:42 - 00863592 _____ C:\Windows\system32\PerfStringBackup.INI 2016-08-25 09:54 - 2014-02-16 13:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-08-25 09:53 - 2016-01-18 19:45 - 00000000 ___DO C:\Users\Com\OneDrive 2016-08-25 09:52 - 2016-06-09 17:00 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture 2016-08-25 09:51 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-08-24 14:54 - 2016-06-14 23:10 - 00033857 _____ C:\Users\Com\Desktop\Untitled 1.ods 2016-08-24 11:39 - 2016-04-27 06:19 - 00000000 ____D C:\Users\Com\Documents\Wichtige Unterlagen 2016-08-24 07:04 - 2016-04-29 07:42 - 00002572 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp.lnk 2016-08-23 00:17 - 2014-02-16 13:39 - 00000000 ____D C:\Users\Com 2016-08-22 21:39 - 2016-05-10 22:45 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1aafcf2bec8d7.job 2016-08-22 21:39 - 2016-05-06 08:37 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1a761d3f62bb1.job 2016-08-22 21:39 - 2016-05-06 08:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-08-21 13:22 - 2016-05-10 22:45 - 00003654 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d1aafcf2bec8d7 2016-08-21 13:22 - 2016-05-06 08:38 - 00003654 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d1a761d3f62bb1 2016-08-21 13:22 - 2016-05-06 08:37 - 00003640 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-08-20 22:34 - 2014-12-29 06:46 - 00000000 ____D C:\Users\Com\AppData\Roaming\vlc 2016-08-20 13:28 - 2015-02-21 19:03 - 00000000 ____D C:\Users\Com\AppData\Roaming\uTorrent 2016-08-20 12:32 - 2015-12-03 11:12 - 00110424 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwtp.sys 2016-08-20 12:32 - 2015-10-06 22:30 - 00087984 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwfp.sys 2016-08-20 12:25 - 2016-04-29 01:28 - 00237400 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys 2016-08-20 01:04 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\ELAM 2016-08-20 01:03 - 2013-08-22 17:36 - 00000000 ___HD C:\Windows\ELAMBKUP 2016-08-20 00:11 - 2016-02-28 23:23 - 00000000 ____D C:\ProgramData\Avira 2016-08-20 00:10 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI 2016-08-19 23:51 - 2016-04-29 07:40 - 00000000 ____D C:\Users\Com\AppData\Local\AvgSetupLog 2016-08-19 23:44 - 2016-02-28 23:23 - 00000000 ____D C:\Program Files (x86)\Avira 2016-08-19 23:37 - 2015-03-06 10:00 - 00000000 ____D C:\ProgramData\Package Cache 2016-08-19 22:20 - 2016-05-06 08:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2016-08-19 16:35 - 2016-04-29 07:42 - 00053008 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\TURegOpt.exe 2016-08-17 12:49 - 2016-04-18 12:55 - 00003350 _____ C:\Windows\System32\Tasks\ESET Windows 10 upgrade – Refresh settings 2016-08-14 19:25 - 2014-12-29 04:27 - 00450560 ___SH C:\Users\Com\Documents\Thumbs.db 2016-08-10 16:57 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps 2016-08-10 16:57 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness 2016-08-09 23:36 - 2014-12-29 04:27 - 00000000 ____D C:\Users\Com\Documents\TranscribeMe 2016-08-09 12:05 - 2016-05-17 10:57 - 00002215 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk ==================== Files in the root of some directories ======= 2014-02-17 04:37 - 2014-02-17 04:37 - 0008194 _____ () C:\Users\Com\AppData\Local\ace11 2015-09-14 21:00 - 2015-09-14 21:00 - 0000016 _____ () C:\ProgramData\mntemp 2015-09-14 21:00 - 2015-09-14 21:00 - 0005050 _____ () C:\ProgramData\wmzddnmb.cix Some files in TEMP: ==================== C:\Users\Com\AppData\Local\Temp\avgnt.exe C:\Users\Com\AppData\Local\Temp\avguirn_08666070450.exe C:\Users\Com\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-08-25 11:59 ==================== End of FRST.txt ============================ FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01 |
Zitat:
![]() Illegale Software: Cracks, Keygens und Co Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems. |
Hallo Cosinus, danke für den Hinweis. Ich wusste nicht, dass das Microsoft Office gecrackt ist. Das Programm war schon auf dem Laptop drauf, als ich es in Thailand gekauft hatte. Ich habe es eh nicht genutzt, weil es alles in Thai ist und ich es nicht lesen kann ;) Ich lösche es gerade. Soll ich danach neuen Log-Dateien versenden? Danke V. |
Zitat:
|
Habe das Ding deinstalliert. Hier kommen die neuen Log-Dateien: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01 Ran by Com (administrator) on USER (25-08-2016 15:13:43) Running from C:\Users\Com\Downloads Loaded Profiles: Com (Available Profiles: Com) Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Atheros Commnucations) C:\Windows\System32\AdminService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avp.exe (Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avpui.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe (Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe (Intel® Corporation) C:\Program Files\Intel\ConnectCenter\bin\CCFManager.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Intel Corporation) C:\Program Files\Intel\STCServ\STCServ.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusSmartGestureDetector64.exe (AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusSGPlusBTServer64.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\scalc.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.exe (Apache Software Foundation) C:\Program Files (x86)\OpenOffice 4\program\soffice.bin (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Windows\System32\prevhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe (Microsoft Corporation) C:\Config.Msi\11607d5.rbf (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated) HKLM\...\Run: [IntelConnectCenter] => C:\Program Files\Intel\ConnectCenter\bin\ICCLauncher.exe [90112 2015-03-16] (Intel® Corporation) HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [247016 2011-09-09] (CyberLink Corp.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [74752 2015-09-02] () HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [204560 2016-08-18] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [226816 2016-05-23] (Geek Software GmbH) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [67864 2016-08-04] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [831576 2016-08-25] (Avira Operations GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53123712 2016-05-17] (Skype Technologies S.A.) HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23375200 2016-07-29] (Google) HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Policies\Explorer: [NoDrives] 0x00000000 IFEO\uninst.exe: [Debugger] "C:\Program Files (x86)\AVG\AVG PC TuneUp\TUAutoReactivator64.exe" ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-07-29] (Google) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Tcpip\..\Interfaces\{C79A7648-F485-45BF-BE3C-29E6202DDFA5}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{FD466CB9-31B0-4EA9-8877-1A184043BC69}: [DhcpNameServer] 192.168.178.1 Internet Explorer: ================== HKU\S-1-5-21-245667631-3740917297-2571881347-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKU\S-1-5-21-245667631-3740917297-2571881347-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-245667631-3740917297-2571881347-1001 -> DefaultScope {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = SearchScopes: HKU\S-1-5-21-245667631-3740917297-2571881347-1001 -> {24E0BF82-5E77-4A8A-A1C7-1F5BCD37122E} URL = SearchScopes: HKU\S-1-5-21-245667631-3740917297-2571881347-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear BHO: Kaspersky Protection -> {03993315-5CE9-4F00-8790-D14A94F1D91A} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\x64\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) BHO: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll [2014-12-15] (DVDVideoSoft Ltd.) BHO-x32: Kaspersky Protection -> {03993315-5CE9-4F00-8790-D14A94F1D91A} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\ssv.dll [2016-04-09] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\jp2ssv.dll [2016-04-09] (Oracle Corporation) BHO-x32: DVDVideoSoft IE Extension -> {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll [2014-12-15] (DVDVideoSoft Ltd.) Toolbar: HKLM - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\x64\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\IEExt\ie_plugin.dll [2015-12-22] (AO Kaspersky Lab) FireFox: ======== FF ProfilePath: C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default FF NetworkProxy: "ftp", "80.77.29.22" FF NetworkProxy: "ftp_port", 80 FF NetworkProxy: "http", "80.77.29.22" FF NetworkProxy: "http_port", 80 FF NetworkProxy: "socks", "80.77.29.22" FF NetworkProxy: "socks_port", 80 FF NetworkProxy: "ssl", "80.77.29.22" FF NetworkProxy: "ssl_port", 80 FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-12] () FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-30] (VideoLAN) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-12] () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\dtplugin\npDeployJava1.dll [2016-04-09] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.77.2 -> C:\Program Files (x86)\Java\jre1.8.0_77\bin\plugin2\npjp2.dll [2016-04-09] (Oracle Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-04-01] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems) FF user.js: detected! => C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\user.js [2016-03-27] FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-06-23] (Adobe Systems Inc.) FF Extension: Avira Browser Safety - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\abs@avira.com [2016-08-19] FF Extension: German Dictionary - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2016-08-16] FF Extension: Diccionario Español Argentina - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\es-AR@dictionaries.addons.mozilla.org [2016-04-06] [not signed] FF Extension: One Click Proxy - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\jid0-zXo3XFGyiDalgkeEO4UYJTUwo2I@jetpack.xpi [2016-04-19] FF Extension: Avira SafeSearch Plus - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\safesearchplus2@avira.com [2016-08-19] FF Extension: Adblock Plus - C:\Users\Com\AppData\Roaming\Mozilla\Firefox\Profiles\n5zlkxd7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28] FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{B64D9B05-48E1-4CEB-BF58-E0643994E900}.xpi [2014-12-15] [not signed] FF HKLM-x32\...\Firefox\Extensions: [light_plugin_ACF0E80077C511E59DED005056C00008@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\FFExt\light_plugin_firefox\addon.xpi FF Extension: Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\FFExt\light_plugin_firefox\addon.xpi [2016-08-20] FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found FF HKU\S-1-5-21-245667631-3740917297-2571881347-1001\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff FF Extension: DVDVideoSoft YouTube MP3 and Video Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-12-24] [not signed] Chrome: ======= CHR DefaultSearchURL: Profile 2 -> hxxps://search.avira.net/#web/result?source=omnibar&q={searchTerms} CHR DefaultSearchKeyword: Profile 2 -> Avira CHR DefaultSuggestURL: Profile 2 -> hxxps://search.avira.net/suggestions?q={searchTerms}&li=ff&hl=en CHR Profile: C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-17] CHR Extension: (Google Docs) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-17] CHR Extension: (Google Drive) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-17] CHR Extension: (YouTube) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-17] CHR Extension: (Google Sheets) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-17] CHR Extension: (Google Docs Offline) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-18] CHR Extension: (Chrome Web Store Payments) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-17] CHR Extension: (Gmail) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-17] CHR Profile: C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Slides) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-26] CHR Extension: (Google Docs) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-26] CHR Extension: (Google Drive) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-26] CHR Extension: (YouTube) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-26] CHR Extension: (Google Sheets) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-26] CHR Extension: (Google Docs Offline) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-26] CHR Extension: (Chrome Web Store Payments) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-26] CHR Extension: (Gmail) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-26] CHR Profile: C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2 CHR Extension: (Google Slides) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-26] CHR Extension: (Google Docs) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-26] CHR Extension: (Google Drive) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-26] CHR Extension: (YouTube) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-26] CHR Extension: (Google Sheets) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-26] CHR Extension: (Avira Browser Safety) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-08-20] CHR Extension: (Google Docs Offline) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-27] CHR Extension: (Avira SafeSearch Plus) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2016-08-20] CHR Extension: (Kaspersky Protection) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lpeeaghdjmhlakojjcgfdhgcejdaefmi [2016-08-20] CHR Extension: (Chrome Web Store Payments) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-26] CHR Extension: (Gmail) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-26] CHR Extension: (Chrome Media Router) - C:\Users\Com\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-20] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ipmkfpcnmccejididiaagpgchgjfajgp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2159320 2016-08-22] (Adobe Systems, Incorporated) S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [988184 2016-08-25] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [470600 2016-08-25] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [470600 2016-08-25] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1453696 2016-08-25] (Avira Operations GmbH & Co. KG) R2 AtherosSvc; C:\Windows\system32\AdminService.exe [208384 2012-08-29] (Atheros Commnucations) [File not signed] R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1097488 2016-08-18] (AVG Technologies CZ, s.r.o.) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [320672 2016-08-04] (Avira Operations GmbH & Co. KG) R2 AviraPhantomVPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [234352 2016-07-29] (Avira Operations GmbH & Co. KG) R2 AVP16.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\avp.exe [236928 2015-12-22] (AO Kaspersky Lab) R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2015-09-02] (Freemake) [File not signed] S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 16.0.1\x64\vssbridge64.exe [152488 2015-12-22] (AO Kaspersky Lab) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 STCServ; C:\Program Files\Intel\STCServ\STCServ.exe [8095456 2015-03-16] (Intel Corporation) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7032080 2016-05-12] (TeamViewer GmbH) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [4878096 2016-08-19] (AVG Technologies CZ, s.r.o.) S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-10-29] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2013-10-31] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2013-10-31] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3855872 2013-09-25] (Qualcomm Atheros Communications, Inc.) R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [69904 2015-10-07] (ASUS Corporation) R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [144664 2016-07-18] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [154392 2016-07-18] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [35488 2016-07-18] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [78208 2016-07-18] (Avira Operations GmbH & Co. KG) R3 bcmsmbsp; C:\Windows\System32\drivers\bcmsmbsp.sys [40152 2013-09-09] (Broadcom Corporation.) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO) S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-03-04] () R3 GPIO; C:\Windows\System32\drivers\iaiogpioe.sys [31232 2013-11-11] (Intel Corporation) R3 iaioi2c; C:\Windows\System32\drivers\iaioi2ce.sys [67584 2013-11-11] (Intel Corporation) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-09-11] (Kaspersky Lab ZAO) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [79752 2015-12-01] (AO Kaspersky Lab) R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [78200 2015-12-02] (AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [30328 2015-06-24] (Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [182664 2015-12-11] (AO Kaspersky Lab) R1 klhk; C:\Windows\System32\drivers\klhk.sys [237400 2016-08-20] (AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [992600 2016-08-20] (AO Kaspersky Lab) R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [51288 2016-04-29] (AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [52608 2015-11-11] (AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45960 2015-12-07] (AO Kaspersky Lab) S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [87984 2016-08-20] (AO Kaspersky Lab) R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [110424 2016-08-20] (AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [194440 2015-12-03] (AO Kaspersky Lab) S3 massfilter; C:\Windows\System32\drivers\ztembbmassfilter.sys [15360 2012-11-23] (MBB Incorporated) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-08-25] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [65408 2016-03-10] (Malwarebytes Corporation) R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-11] (Intel Corporation) S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.) S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(???? | ????? ???? ?????.)) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-03-29] (AVG Netherlands B.V.) R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2013-10-31] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [236888 2013-10-31] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2013-10-31] (Microsoft Corporation) S3 WUDFWpdComp; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation) S3 ZTEusbmdm6k; C:\Windows\system32\DRIVERS\ztembbusbmdm.sys [123264 2012-11-23] (ZTE Incorporated) S3 ZTEusbnmea; C:\Windows\system32\DRIVERS\ztembbusbnmea.sys [123264 2012-11-23] (ZTE Incorporated) S3 ZTEusbser6K; C:\Windows\system32\DRIVERS\ztembbusbser6k.sys [123264 2012-11-23] (ZTE Incorporated) S3 ZTEusbvoice; C:\Windows\system32\DRIVERS\ztembbusbvoice.sys [123264 2012-11-23] (ZTE Incorporated) U4 klkbdflt2; \SystemRoot\system32\DRIVERS\klkbdflt2.sys [X] S4 nvlddmkm; \SystemRoot\system32\DRIVERS\nvlddmkm.sys [X] S4 nvpciflt; \SystemRoot\system32\DRIVERS\nvpciflt.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-25 14:12 - 2016-08-25 14:12 - 00046533 _____ C:\Users\Com\Desktop\FRST.txt 2016-08-25 14:12 - 2016-08-25 14:12 - 00032675 _____ C:\Users\Com\Desktop\Addition.txt 2016-08-25 14:08 - 2016-08-25 14:11 - 00032675 _____ C:\Users\Com\Downloads\Addition.txt 2016-08-25 14:06 - 2016-08-25 15:14 - 00027722 _____ C:\Users\Com\Downloads\FRST.txt 2016-08-25 14:05 - 2016-08-25 15:13 - 00000000 ____D C:\FRST 2016-08-25 14:05 - 2016-08-25 14:05 - 02396672 _____ (Farbar) C:\Users\Com\Downloads\FRST64.exe 2016-08-25 13:23 - 2016-08-25 13:23 - 00000091 ____H C:\Users\Com\Desktop\.~lock.cv roman.doc# 2016-08-25 12:53 - 2016-08-25 12:53 - 00411216 _____ C:\Users\Com\Downloads\ceo_resume_template.pdf 2016-08-25 12:52 - 2016-08-25 12:52 - 00169358 _____ C:\Users\Com\Desktop\sample-CEO-resume.pdf 2016-08-25 12:51 - 2016-08-25 12:51 - 00178626 _____ C:\Users\Com\Downloads\sample-CEO-resume.pdf 2016-08-25 12:30 - 2016-08-25 12:30 - 00012362 _____ C:\Users\Com\Downloads\Sample CV in English.pdf 2016-08-24 16:31 - 2016-08-25 13:14 - 00019186 _____ C:\Users\Com\Desktop\cv roman.odt 2016-08-24 14:45 - 2016-08-24 14:45 - 00096514 _____ C:\Users\Com\Downloads\dfg_initiativ_2012.pdf 2016-08-23 20:43 - 2016-08-23 20:43 - 00154656 _____ C:\Users\Com\Downloads\fb03-0010-frsek-260816(1).pdf 2016-08-23 20:40 - 2016-08-23 20:40 - 00154656 _____ C:\Users\Com\Downloads\fb03-0010-frsek-260816.pdf 2016-08-23 09:33 - 2016-08-25 09:54 - 00001537 _____ C:\Users\Com\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AsusSmartGestureDetector.lnk 2016-08-20 22:30 - 2016-08-20 22:30 - 30166566 _____ C:\Users\Com\Downloads\DSCN1595.MOV 2016-08-20 20:15 - 2016-08-20 20:16 - 91467869 _____ C:\Users\Com\Downloads\DSCN1568.MOV 2016-08-20 20:11 - 2016-08-20 20:11 - 37532381 _____ C:\Users\Com\Downloads\DSCN1547.MOV 2016-08-20 20:10 - 2016-08-20 20:11 - 48410081 _____ C:\Users\Com\Downloads\DSCN1546.MOV 2016-08-20 19:07 - 2016-08-20 19:07 - 21830775 _____ C:\Users\Com\Downloads\DSCN1600.MOV 2016-08-20 19:07 - 2016-08-20 19:07 - 10102483 _____ C:\Users\Com\Downloads\DSCN1553.MOV 2016-08-20 19:06 - 2016-08-20 19:07 - 17810256 _____ C:\Users\Com\Downloads\DSCN1599.MOV 2016-08-20 19:06 - 2016-08-20 19:06 - 11296539 _____ C:\Users\Com\Downloads\DSCN1598.MOV 2016-08-20 19:04 - 2016-08-20 19:04 - 21394464 _____ C:\Users\Com\Downloads\DSCN1597.MOV 2016-08-20 19:03 - 2016-08-20 19:03 - 16439466 _____ C:\Users\Com\Downloads\DSCN1596.MOV 2016-08-20 18:59 - 2016-08-20 19:00 - 48668490 _____ C:\Users\Com\Downloads\DSCN1602.MOV 2016-08-20 14:51 - 2016-08-21 11:23 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\47F665AA.sys 2016-08-20 14:35 - 2016-08-20 14:35 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\4F505988.sys 2016-08-20 01:04 - 2016-08-20 01:04 - 00002107 _____ C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2016-08-20 01:04 - 2016-08-20 01:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2016-08-20 01:03 - 2016-08-25 14:27 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2016-08-20 01:03 - 2016-08-20 01:03 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2016-08-20 01:03 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2016-08-20 01:02 - 2016-08-20 12:32 - 00992600 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys 2016-08-20 01:02 - 2015-12-11 17:31 - 00182664 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys 2016-08-20 00:47 - 2016-08-20 00:47 - 01932640 _____ (Kaspersky Lab) C:\Users\Com\Downloads\kav16.0.0.614abcdde_9831.exe 2016-08-20 00:06 - 2016-08-20 00:06 - 02041880 _____ (Kaspersky Lab) C:\Users\Com\Downloads\kav16.0.1.445abcde_10532.exe 2016-08-19 23:50 - 2016-08-19 23:50 - 03143504 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Com\Downloads\AVG_Protection_Free_1606.exe 2016-08-19 23:44 - 2016-08-19 23:44 - 00001068 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira Phantom VPN.lnk 2016-08-19 23:44 - 2016-08-19 23:44 - 00001056 _____ C:\Users\Public\Desktop\Avira Phantom VPN.lnk 2016-08-19 23:44 - 2016-08-19 23:44 - 00000000 ____D C:\Users\Com\AppData\Roaming\Avira 2016-08-19 23:40 - 2016-07-18 16:23 - 00154392 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2016-08-19 23:40 - 2016-07-18 16:23 - 00144664 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2016-08-19 23:40 - 2016-07-18 16:23 - 00078208 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2016-08-19 23:40 - 2016-07-18 16:23 - 00035488 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2016-08-19 23:38 - 2016-08-19 23:38 - 04831216 _____ (Avira Operations GmbH & Co. KG) C:\Users\Com\Downloads\avira_en_av_57b77bc3aa496__ws(1).exe 2016-08-19 23:37 - 2016-08-25 10:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2016-08-19 23:37 - 2016-08-19 23:37 - 00001222 _____ C:\Users\Public\Desktop\Avira Launcher.lnk 2016-08-19 23:36 - 2016-08-19 23:36 - 04831216 _____ (Avira Operations GmbH & Co. KG) C:\Users\Com\Downloads\avira_en_av_57b77bc3aa496__ws.exe 2016-08-19 23:25 - 2016-08-25 14:53 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-08-19 23:25 - 2016-08-19 23:25 - 00001114 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-08-19 23:25 - 2016-08-19 23:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-08-19 23:25 - 2016-08-19 23:25 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-08-19 23:25 - 2016-08-19 23:25 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-08-19 23:25 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-08-19 23:25 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-08-19 23:25 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-08-19 23:24 - 2016-08-19 23:24 - 22851472 _____ (Malwarebytes ) C:\Users\Com\Downloads\mbam-setup-2.2.1.1043.exe 2016-08-19 18:13 - 2016-08-19 18:13 - 00074187 _____ C:\Users\Com\Downloads\ma_polwis_zugangssatzung.pdf 2016-08-18 21:56 - 2016-08-19 23:25 - 00025156 _____ C:\Users\Com\Desktop\Untitled 1.odt 2016-08-18 20:09 - 2016-08-18 20:09 - 00028158 _____ C:\Users\Com\Downloads\Anlage(1).pdf 2016-08-18 19:48 - 2016-08-18 19:48 - 03746280 _____ C:\Users\Com\Downloads\broschuere-berufsbilder-im-sprachendienst-11-data.pdf 2016-08-16 21:06 - 2016-08-16 21:06 - 00014239 _____ C:\Users\Com\Documents\Untitled 1.odt 2016-08-16 18:28 - 2016-08-16 18:28 - 02397951 _____ C:\Users\Com\Downloads\Veranstaltungsprogramm und Anmeldeformular.als PDF.pdf 2016-08-12 13:15 - 2016-08-12 13:15 - 04014191 _____ C:\Users\Com\Desktop\Bewerbungsmappe_V.Stanislavski_AA Frankfurt.pdf 2016-08-12 12:11 - 2016-08-12 12:18 - 00058981 _____ C:\Users\Com\Desktop\Nachweis Eigenbemühungen V.Stanislavski.pdf 2016-08-12 12:07 - 2016-08-12 12:07 - 00061012 _____ C:\Users\Com\Documents\Nachweis Eigenbemühungen V.Stanislavski.pdf 2016-08-10 21:08 - 2016-08-10 21:08 - 00023214 _____ C:\Users\Com\Documents\AA.odt 2016-08-09 14:49 - 2016-08-09 14:49 - 00129474 _____ C:\Users\Com\Downloads\egov-content438289.pdf 2016-08-09 14:47 - 2016-08-09 14:47 - 00143605 _____ C:\Users\Com\Downloads\l6019022dstbai808947.pdf 2016-08-09 14:32 - 2016-08-09 14:32 - 00676466 _____ C:\Users\Com\Downloads\eb-sgbiii-443-0-pdf.pdf 2016-08-09 12:37 - 2016-08-09 12:37 - 02468086 _____ C:\Users\Com\Downloads\Sfs_Studie.pdf 2016-08-09 01:14 - 2016-08-09 01:14 - 00053785 _____ C:\Users\Com\Downloads\data.pdf 2016-08-09 00:33 - 2016-08-09 00:33 - 08793295 _____ C:\Users\Com\Downloads\6019022dstbai386915.pdf 2016-08-08 14:11 - 2016-08-08 14:11 - 00082002 _____ C:\Users\Com\Downloads\tvoed-bund(1).pdf 2016-08-08 11:58 - 2016-08-08 11:58 - 10046619 _____ C:\Users\Com\Downloads\l6019022dstbai665890.pdf 2016-08-08 07:13 - 2016-08-08 07:13 - 00049485 _____ C:\Users\Com\Documents\Test_translation_2_V.Stanislavski.pdf 2016-08-08 07:13 - 2016-08-08 07:13 - 00048708 _____ C:\Users\Com\Documents\Test_translation_1_V.Stanislavski.pdf 2016-08-06 19:22 - 2016-08-06 19:22 - 04498815 _____ C:\Users\Com\Downloads\Weissbuch2016_barrierefrei.pdf 2016-08-06 19:22 - 2016-08-06 19:22 - 04498815 _____ C:\Users\Com\Downloads\Weissbuch2016_barrierefrei(1).pdf 2016-08-06 18:58 - 2016-08-06 18:58 - 00016473 _____ C:\Users\Com\Downloads\Auswahlverfahren.pdf 2016-08-05 12:44 - 2016-08-05 12:45 - 04235939 _____ C:\Users\Com\Downloads\tpi125_de_en.pdf 2016-08-03 13:44 - 2016-08-03 13:44 - 00121863 _____ C:\Users\Com\Downloads\Form(4).pdf 2016-08-03 13:43 - 2016-08-03 13:43 - 00059748 _____ C:\Users\Com\Downloads\Registrierungsbestätigung.PDF 2016-08-03 13:42 - 2016-08-03 13:42 - 00121863 _____ C:\Users\Com\Downloads\Form(3).pdf 2016-08-03 13:42 - 2016-08-03 13:42 - 00121863 _____ C:\Users\Com\Downloads\Form(2).pdf 2016-08-03 13:41 - 2016-08-03 13:42 - 00122956 _____ C:\Users\Com\Downloads\Form(1).pdf 2016-08-03 13:41 - 2016-08-03 13:41 - 00122956 _____ C:\Users\Com\Downloads\Form.pdf 2016-08-03 12:15 - 2016-08-03 12:15 - 00082002 _____ C:\Users\Com\Downloads\tvoed-bund.pdf 2016-08-02 22:17 - 2016-08-02 22:17 - 00390997 _____ C:\Users\Com\Downloads\UdOe30.pdf 2016-08-01 17:03 - 2016-08-17 00:34 - 00082071 _____ C:\Users\Com\Documents\Übersetzung.odt 2016-08-01 14:29 - 2016-08-01 14:29 - 00339808 _____ C:\Users\Com\Downloads\TOEFL_V.Stanislavski.pdf 2016-07-30 16:55 - 2016-07-30 16:55 - 02172833 _____ C:\Users\Com\Downloads\Arbeitszeugnisse_V.Stanislavski.pdf 2016-07-30 13:17 - 2016-07-30 13:17 - 00118450 _____ C:\Users\Com\Downloads\Merkblatt_SA_in_der_UA_Web_2015-1611.pdf 2016-07-29 12:28 - 2016-07-29 12:28 - 00388067 _____ C:\Users\Com\Downloads\Daten#bersicht 2016-07-29 12:15 - 2016-07-29 12:15 - 02263569 _____ C:\Users\Com\Downloads\160722_Stellenanzeige_Projektmanager_Bremen.pdf 2016-07-29 11:33 - 2016-07-29 11:33 - 01746479 _____ C:\Users\Com\Documents\Bildungszeugnisse_V.Stanislavski.pdf 2016-07-29 11:32 - 2016-07-29 11:32 - 01038107 _____ C:\Users\Com\Documents\Arbeitszeugnisse_V.Stanislavski.pdf 2016-07-29 10:02 - 2016-08-22 21:39 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1e96f7ed57473.job 2016-07-29 10:02 - 2016-08-22 21:39 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-07-29 10:02 - 2016-08-21 13:22 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d1e96f7ed57473 2016-07-29 10:02 - 2016-08-21 13:22 - 00003890 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-07-28 18:10 - 2016-07-28 18:10 - 07422017 _____ C:\Users\Com\Downloads\Bewerbung.pdf 2016-07-28 17:44 - 2016-07-28 17:44 - 07263884 _____ C:\Users\Com\Downloads\Bewerbungsprofil.pdf 2016-07-28 16:35 - 2016-07-28 16:35 - 00840274 _____ C:\Users\Com\Documents\Zeugnisse_V. Stanislavski.pdf 2016-07-28 15:42 - 2016-07-28 15:42 - 00196363 _____ C:\Users\Com\Downloads\2016-06-25_Praktikum_Intendanz_IFB.pdf 2016-07-27 18:43 - 2016-07-27 18:43 - 00088179 _____ C:\Users\Com\Downloads\20160706_Ausschreibung F 44.pdf 2016-07-26 16:58 - 2016-07-26 16:58 - 00925992 _____ C:\Users\Com\Downloads\uepo_300_2010_2013-09-22.pdf 2016-07-26 16:31 - 2016-07-26 16:31 - 05987736 _____ C:\Users\Com\Downloads\infoNRW_1_2014_online.pdf 2016-07-26 15:52 - 2016-07-26 18:34 - 00013568 _____ C:\Users\Com\Documents\Kalkulation_Matrix.ods 2016-07-26 12:05 - 2016-07-26 12:27 - 00968071 _____ C:\Users\Com\Documents\Bewerbungsmappe_V.Stanislavski_AfA_Montabaur.pdf ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-25 15:14 - 2014-02-17 04:18 - 00000000 ____D C:\Users\Com\AppData\Roaming\Skype 2016-08-25 15:10 - 2014-02-16 13:45 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-245667631-3740917297-2571881347-1001 2016-08-25 15:07 - 2014-02-16 13:44 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2016-08-25 15:05 - 2013-08-22 21:11 - 00000000 ____D C:\Windows\ShellNew 2016-08-25 15:05 - 2013-08-22 17:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2016-08-25 14:58 - 2016-04-10 12:05 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-08-25 14:57 - 2013-08-22 15:25 - 00000076 _____ C:\Windows\win.ini 2016-08-25 14:54 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2016-08-25 14:53 - 2014-12-29 17:06 - 06140928 ___SH C:\Users\Com\Desktop\Thumbs.db 2016-08-25 13:22 - 2014-12-17 09:00 - 07687168 ___SH C:\Users\Com\Downloads\Thumbs.db 2016-08-25 11:58 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf 2016-08-25 09:59 - 2014-02-17 04:36 - 00000000 ____D C:\Users\Com\AppData\Local\Adobe 2016-08-25 09:58 - 2014-12-16 17:22 - 00003902 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{73BFAA1B-1E35-478D-B893-0170BDE89573} 2016-08-25 09:56 - 2014-02-16 13:42 - 00863592 _____ C:\Windows\system32\PerfStringBackup.INI 2016-08-25 09:54 - 2014-02-16 13:55 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-08-25 09:53 - 2016-01-18 19:45 - 00000000 ___DO C:\Users\Com\OneDrive 2016-08-25 09:52 - 2016-06-09 17:00 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture 2016-08-25 09:51 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-08-24 14:54 - 2016-06-14 23:10 - 00033857 _____ C:\Users\Com\Desktop\Untitled 1.ods 2016-08-24 11:39 - 2016-04-27 06:19 - 00000000 ____D C:\Users\Com\Documents\Wichtige Unterlagen 2016-08-24 07:04 - 2016-04-29 07:42 - 00002572 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp.lnk 2016-08-23 00:17 - 2014-02-16 13:39 - 00000000 ____D C:\Users\Com 2016-08-22 21:39 - 2016-05-10 22:45 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1aafcf2bec8d7.job 2016-08-22 21:39 - 2016-05-06 08:37 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1a761d3f62bb1.job 2016-08-22 21:39 - 2016-05-06 08:37 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-08-21 13:22 - 2016-05-10 22:45 - 00003654 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d1aafcf2bec8d7 2016-08-21 13:22 - 2016-05-06 08:38 - 00003654 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d1a761d3f62bb1 2016-08-21 13:22 - 2016-05-06 08:37 - 00003640 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-08-20 22:34 - 2014-12-29 06:46 - 00000000 ____D C:\Users\Com\AppData\Roaming\vlc 2016-08-20 13:28 - 2015-02-21 19:03 - 00000000 ____D C:\Users\Com\AppData\Roaming\uTorrent 2016-08-20 12:32 - 2015-12-03 11:12 - 00110424 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwtp.sys 2016-08-20 12:32 - 2015-10-06 22:30 - 00087984 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwfp.sys 2016-08-20 12:25 - 2016-04-29 01:28 - 00237400 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys 2016-08-20 01:04 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\ELAM 2016-08-20 01:03 - 2013-08-22 17:36 - 00000000 ___HD C:\Windows\ELAMBKUP 2016-08-20 00:11 - 2016-02-28 23:23 - 00000000 ____D C:\ProgramData\Avira 2016-08-20 00:10 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI 2016-08-19 23:51 - 2016-04-29 07:40 - 00000000 ____D C:\Users\Com\AppData\Local\AvgSetupLog 2016-08-19 23:44 - 2016-02-28 23:23 - 00000000 ____D C:\Program Files (x86)\Avira 2016-08-19 23:37 - 2015-03-06 10:00 - 00000000 ____D C:\ProgramData\Package Cache 2016-08-19 22:20 - 2016-05-06 08:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive 2016-08-19 16:35 - 2016-04-29 07:42 - 00053008 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\TURegOpt.exe 2016-08-17 12:49 - 2016-04-18 12:55 - 00003350 _____ C:\Windows\System32\Tasks\ESET Windows 10 upgrade – Refresh settings 2016-08-14 19:25 - 2014-12-29 04:27 - 00450560 ___SH C:\Users\Com\Documents\Thumbs.db 2016-08-10 16:57 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps 2016-08-10 16:57 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness 2016-08-09 23:36 - 2014-12-29 04:27 - 00000000 ____D C:\Users\Com\Documents\TranscribeMe 2016-08-09 12:05 - 2016-05-17 10:57 - 00002215 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk ==================== Files in the root of some directories ======= 2014-02-17 04:37 - 2014-02-17 04:37 - 0008194 _____ () C:\Users\Com\AppData\Local\ace11 2015-09-14 21:00 - 2015-09-14 21:00 - 0000016 _____ () C:\ProgramData\mntemp 2015-09-14 21:00 - 2015-09-14 21:00 - 0005050 _____ () C:\ProgramData\wmzddnmb.cix Some files in TEMP: ==================== C:\Users\Com\AppData\Local\Temp\avgnt.exe C:\Users\Com\AppData\Local\Temp\avguirn_08666070450.exe C:\Users\Com\AppData\Local\Temp\ose00000.exe C:\Users\Com\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-08-25 11:59 ==================== End of FRST.txt ============================ FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01 |
Bitte die CODE-Tags korrigieren. Avira ist immer noch drauf. Das sollte runter. Deinstallier auch die Reste von AVG wenn möglich. |
Habe Avira und AVG deinstalliert. Auf ein Neues: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21-08-2016 01 --- --- --- [CODE]Additional FRST Logfile: Code: scan result of Farbar Recovery Scan Tool (x64) Version: 21-08-2016 01 |
Ok weiter mit MBAR Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers |
Es kam die Meldung: Congratulation! No clean up is required. No malware found |
bitte immer die logfiles posten |
Alle Zeitangaben in WEZ +1. Es ist jetzt 05:08 Uhr. |
Copyright ©2000-2025, Trojaner-Board