~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.3 (03.23.2014:1)
OS: Windows Vista (TM) Home Basic x86
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\protector_dll.protectorbho.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\complitly.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\escort.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\genericasktoolbar.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\tdataprotocol.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\updatebho.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\wit4ie.dll
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{6C434537-053E-486D-B62A-160059D9D456}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\blabbers
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\complitly
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\installcore
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\powerpack
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\browsercompanion
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\bbylntlbr.bbylntlbrhlpr.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\base64
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\chrome
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\protocols\handler\prox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updatebho.timerbho
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\updatebho.timerbho.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT2504091
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F7D1BF13-7972-4647-A5E9-880B1ADEB147}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{B166D7A5-26D0-466D-BD7B-6BCCD458A5A3}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{963B125B-8B21-49A2-A3A8-E37092276531}
~~~ Files
Successfully deleted: [File] "C:\Windows\System32\Tasks\scheduled update for ask toolbar"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\Wadija & Ibo\AppData\Roaming\complitly"
~~~ FireFox
Successfully deleted: [File] C:\user.js
user_pref("CT2504091.129079840421401584.isToggled_item0_11", "true");
user_pref("CT2504091.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT2504091.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2504091.FirstTime", "true");
user_pref("CT2504091.FirstTimeFF3", "true");
user_pref("CT2504091.UserID", "UN92379638955308068");
user_pref("CT2504091.addressBarTakeOverEnabledInHidden", "true");
user_pref("CT2504091.autoDisableScopes", -1);
user_pref("CT2504091.countryCode", "IR");
user_pref("CT2504091.defaultSearch", "false");
user_pref("CT2504091.embeddedsData", "[{\"appId\":\"129079840422026594\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"get
user_pref("CT2504091.enableAlerts", "false");
user_pref("CT2504091.enableFix404ByUser", "FALSE");
user_pref("CT2504091.enableSearchFromAddressBar", "true");
user_pref("CT2504091.firstTimeDialogOpened", "true");
user_pref("CT2504091.fixPageNotFoundError", "true");
user_pref("CT2504091.fixPageNotFoundErrorByUser", "true");
user_pref("CT2504091.fixPageNotFoundErrorInHidden", "true");
user_pref("CT2504091.fixUrls", true);
user_pref("CT2504091.fullUserID", "UN92379638955308068.UP.20130701212245");
user_pref("CT2504091.installId", "ConduitNSISIntegration");
user_pref("CT2504091.installType", "ConduitNSISIntegration");
user_pref("CT2504091.isCheckedStartAsHidden", true);
user_pref("CT2504091.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT2504091.isFirstTimeToolbarLoading", "false");
user_pref("CT2504091.isNewTabEnabled", false);
user_pref("CT2504091.isPerformedSmartBarTransition", "true");
user_pref("CT2504091.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2504091.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?gd=&ctid=CT2504091&octid=CT2504091&ISID=ISID_ID&SearchSource=15&CUI=
user_pref("CT2504091.lastVersion", "10.23.0.822");
user_pref("CT2504091.migrateAppsAndComponents", true);
user_pref("CT2504091.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.trojaner-board.de%2F151372-windows-vista-aktives-fenster-minimier-selbststaendig.html\"
user_pref("CT2504091.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT2504091.openThankYouPage", "false");
user_pref("CT2504091.openUninstallPage", "false");
user_pref("CT2504091.search.searchAppId", "129079840422026594");
user_pref("CT2504091.search.searchCount", "0");
user_pref("CT2504091.searchInNewTabEnabled", "false");
user_pref("CT2504091.searchInNewTabEnabledByUser", "false");
user_pref("CT2504091.searchInNewTabEnabledInHidden", "true");
user_pref("CT2504091.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
user_pref("CT2504091.searchSuggestEnabledByUser", "false");
user_pref("CT2504091.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2504091.sendUsageEnabled", "false");
user_pref("CT2504091.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
user_pref("CT2504091.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2504091\"}");
user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://VuzeRemote.OurToolbar.com//xpi\"}");
user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Vuze Remote \"}");
user_pref("CT2504091.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
user_pref("CT2504091.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
user_pref("CT2504091.serviceLayer_services_Configuration_lastUpdate", "1395751010508");
user_pref("CT2504091.serviceLayer_services_appTrackingFirstTime_lastUpdate", "1378563417035");
user_pref("CT2504091.serviceLayer_services_appsMetadata_lastUpdate", "1378563422448");
user_pref("CT2504091.serviceLayer_services_clientErrorLog_lastUpdate", "1345554902331");
user_pref("CT2504091.serviceLayer_services_gottenAppsContextMenu_lastUpdate", "1378563416906");
user_pref("CT2504091.serviceLayer_services_login_10.10.26.4_lastUpdate", "1345623379777");
user_pref("CT2504091.serviceLayer_services_login_10.10.27.6_lastUpdate", "1372693813689");
user_pref("CT2504091.serviceLayer_services_login_10.16.4.519_lastUpdate", "1374835789376");
user_pref("CT2504091.serviceLayer_services_login_10.20.0.513_lastUpdate", "1379767644315");
user_pref("CT2504091.serviceLayer_services_login_10.21.1.507_lastUpdate", "1383902747739");
user_pref("CT2504091.serviceLayer_services_login_10.22.2.530_lastUpdate", "1384428915469");
user_pref("CT2504091.serviceLayer_services_login_10.22.3.518_lastUpdate", "1386518425619");
user_pref("CT2504091.serviceLayer_services_login_10.22.5.510_lastUpdate", "1388979703699");
user_pref("CT2504091.serviceLayer_services_login_10.23.0.822_lastUpdate", "1395751011734");
user_pref("CT2504091.serviceLayer_services_optimizer_lastUpdate", "1345554901173");
user_pref("CT2504091.serviceLayer_services_otherAppsContextMenu_lastUpdate", "1378563416961");
user_pref("CT2504091.serviceLayer_services_searchAPI_lastUpdate", "1395751012760");
user_pref("CT2504091.serviceLayer_services_serviceMap_lastUpdate", "1395751010062");
user_pref("CT2504091.serviceLayer_services_toolbarContextMenu_lastUpdate", "1378563416789");
user_pref("CT2504091.serviceLayer_services_toolbarSettings_lastUpdate", "1395751010137");
user_pref("CT2504091.serviceLayer_services_translation_lastUpdate", "1395751010490");
user_pref("CT2504091.settingsINI", true);
user_pref("CT2504091.shouldFirstTimeDialog", "false");
user_pref("CT2504091.showToolbarPermission", "false");
user_pref("CT2504091.smartbar.CTID", "CT2504091");
user_pref("CT2504091.smartbar.Uninstall", "0");
user_pref("CT2504091.smartbar.toolbarName", "Vuze Remote ");
user_pref("CT2504091.startPage", "userChanged");
user_pref("CT2504091.toolbarBornServerTime", "21-8-2012");
user_pref("CT2504091.toolbarCurrentServerTime", "25-3-2014");
user_pref("CT2504091.toolbarLoginClientTime", "Mon Jul 01 2013 21:22:49 GMT+0430 (Iran Sommerzeit)");
user_pref("CT2504091.upgradeFromClearSBVersion", true);
user_pref("CT2504091_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1395753918954,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}
user_pref("extensions.BabylonToolbar_i.aflt", "babsst");
user_pref("extensions.BabylonToolbar_i.babExt", "");
user_pref("extensions.BabylonToolbar_i.babTrack", "affID=111316&tt=010712_2");
user_pref("extensions.BabylonToolbar_i.hardId", "70817c420000000000000c607698441a");
user_pref("extensions.BabylonToolbar_i.id", "70817c420000000000000c607698441a");
user_pref("extensions.BabylonToolbar_i.instlDay", "15526");
user_pref("extensions.BabylonToolbar_i.instlRef", "sst");
user_pref("extensions.BabylonToolbar_i.prdct", "BabylonToolbar");
user_pref("extensions.BabylonToolbar_i.prtnrId", "babylon");
user_pref("extensions.BabylonToolbar_i.smplGrp", "none");
user_pref("extensions.BabylonToolbar_i.srcExt", "ss");
user_pref("extensions.BabylonToolbar_i.tlbrId", "base");
user_pref("extensions.BabylonToolbar_i.vrsn", "1.5.3.17");
user_pref("extensions.BabylonToolbar_i.vrsnTs", "1.5.3.1718:10:02");
user_pref("extensions.BabylonToolbar_i.vrsni", "1.5.3.17");
user_pref("extensions.asktb.ff-original-keyword-url", "");
user_pref("plugin.state.npconduitfirefoxplugin", 2);
user_pref("smartbar.machineId", "UI+WRFAQ5UPNQY2C/FQDRUJPGJW3FUTJ3UCZHZ+D2MI+POWR7JLP5772MEVOUY+E1/ZMQWZMHKNBSICR+MK2GA");
Emptied folder: C:\Users\Wadija & Ibo\AppData\Roaming\mozilla\firefox\profiles\hvu1rdbs.default\minidumps [61 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.03.2014 at 18:28:29,75
Computer was rebooted
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
AdwCleaner Logfile:
Code:
# AdwCleaner v3.022 - Bericht erstellt am 25/03/2014 um 18:55:39
# Aktualisiert 13/03/2014 von Xplode
# Betriebssystem : Windows Vista (TM) Home Basic Service Pack 2 (32 bits)
# Benutzername : Wadija & Ibo - IRAN
# Gestartet von : C:\Users\Wadija & Ibo\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\Wadija & Ibo\AppData\Roaming\Mozilla\Firefox\Profiles\hvu1rdbs.default\ValueApps
Datei Gelöscht : C:\Users\Wadija & Ibo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tcbhn.lnk
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bodddioamolcibagionmmobehnbhiakf
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\dlfienamagdnkekbbbocojppncdambda
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1FC26DE0-5BF4-46B5-8629-D6484FFC675A}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1FC26DE0-5BF4-46B5-8629-D6484FFC675A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{20EDC024-43C5-423E-B7F5-FD93523E0D9F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{373ED12D-B306-43AC-9485-A7C5133DC34C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{442F13BC-2031-42D5-9520-437F65271153}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{ED6535E7-F778-48A5-A060-549D30024511}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{817923CB-4744-4216-B250-CF7EDA8F1767}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9F0C17EB-EF2C-4278-9136-2D547656BC03}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C9AE652B-8C99-4AC2-B556-8B501182874E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{01BCB858-2F62-4F06-A8F4-48F927C15333}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{955B782E-CDC8-4CEE-B6F6-AD7D541A8D8A}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{0FB6A909-6086-458F-BD92-1F8EE10042A0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{963B125B-8B21-49A2-A3A8-E37092276531}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
Schlüssel Gelöscht : HKCU\Software\Ask.com
Schlüssel Gelöscht : HKCU\Software\Blabbers
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\AskToolbar
Schlüssel Gelöscht : HKLM\Software\Cheat Engine\OpenCandy
Schlüssel Gelöscht : HKLM\Software\SimplyGen
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{4FFBB818-B13C-11E0-931D-B2664824019B}_is1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BrowserCompanion
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v9.0.8112.16540
-\\ Mozilla Firefox v27.0.1 (de)
[ Datei : C:\Users\Wadija & Ibo\AppData\Roaming\Mozilla\Firefox\Profiles\hvu1rdbs.default\prefs.js ]
Zeile gelöscht : user_pref("CT2504091.ENABALE_HISTORY", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT2504091.ENABLE_RETURN_WEB_SEARCH_ON_THE_PAGE", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2504091.embeddedsData", "[{\"appId\":\"129079840422026594\",\"apiPermissions\":{\"crossDomainAjax\":true,\"getMainFrameTitle\":true,\"getMainFrameUrl\":true,\"getSearchTerm\":true,\"insta[...]
Zeile gelöscht : user_pref("CT2504091.isEnableAllDialogs", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT2504091.isToolbarShrinked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2504091.lastNewTabSettings", "{\"isEnabled\":false,\"newTabUrl\":\"hxxp://search.conduit.com/?gd=&ctid=CT2504091&octid=CT2504091&ISID=ISID_ID&SearchSource=15&CUI=UN92379638955308068&SSPV=[...]
Zeile gelöscht : user_pref("CT2504091.navigationAliasesJson", "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.trojaner-board.de%2F151372-windows-vista-aktives-fenster-minimier-selbststaendig.html\",\"EB_MAIN_FRAME_TITLE\":[...]
Zeile gelöscht : user_pref("CT2504091.newSettings", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2504091.searchProtector.notifyChanges", "{\"dataType\":\"string\",\"data\":\"false\"}");
Zeile gelöscht : user_pref("CT2504091.selectToSearchBoxEnabled", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2504091.serviceLayer_service_login_isFirstLoginInvoked", "{\"dataType\":\"boolean\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2504091.serviceLayer_service_login_loginCount", "{\"dataType\":\"number\",\"data\":\"4\"}");
Zeile gelöscht : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeCTID", "{\"dataType\":\"string\",\"data\":\"CT2504091\"}");
Zeile gelöscht : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeDownloadUrl", "{\"dataType\":\"string\",\"data\":\"hxxp://VuzeRemote.OurToolbar.com//xpi\"}");
Zeile gelöscht : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_activeToolbarName", "{\"dataType\":\"string\",\"data\":\"Vuze Remote \"}");
Zeile gelöscht : user_pref("CT2504091.serviceLayer_service_toolbarGrouping_invoked", "{\"dataType\":\"string\",\"data\":\"true\"}");
Zeile gelöscht : user_pref("CT2504091.serviceLayer_service_usage_toolbarUsageCount", "{\"dataType\":\"number\",\"data\":\"2\"}");
Zeile gelöscht : user_pref("CT2504091_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1395753918954,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0}]");
Zeile gelöscht : user_pref("extensions.wrc.SearchRules.rambler.ru.style", ".WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url(\"IMAGE\") right no-repeat}");
Zeile gelöscht : user_pref("valueApps.CT2504091.mam_gk_currentVersion", "312E31332E302E3137");
Zeile gelöscht : user_pref("valueApps.CT2504091.mam_gk_currentVersion.storedInFile", false);
Zeile gelöscht : user_pref("valueApps.CT2504091.mam_gk_migrated_from_ls", "31");
Zeile gelöscht : user_pref("valueApps.CT2504091.mam_gk_migrated_from_ls.storedInFile", false);
Zeile gelöscht : user_pref("valueApps.CT2504091.mam_gk_userBornDate", "4E2F41");
Zeile gelöscht : user_pref("valueApps.CT2504091.mam_gk_userBornDate.storedInFile", false);
*************************
AdwCleaner[R0].txt - [23176 octets] - [25/03/2014 17:50:15]
AdwCleaner[R1].txt - [22577 octets] - [25/03/2014 17:52:52]
AdwCleaner[R2].txt - [8105 octets] - [25/03/2014 18:54:52]
AdwCleaner[S0].txt - [1116 octets] - [25/03/2014 17:51:20]
AdwCleaner[S1].txt - [370 octets] - [25/03/2014 17:54:09]
AdwCleaner[S2].txt - [8042 octets] - [25/03/2014 18:55:39]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [8102 octets] ##########
--- --- ---
vielen dank soweit
aber ein kleines Problem gibt es noch, anti malware hängt sich immer auf wenn ich den scan log exportieren will als txt file und dann steht da keine rückmeldung und das programm funktioniert nicht mehr richtig
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Wadija & Ibo (administrator) on IRAN on 25-03-2014 19:07:36
Running from C:\Users\Wadija & Ibo\Desktop
Microsoft® Windows Vista™ Home Basic Service Pack 2 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
() C:\Windows\System32\WLTRYSVC.EXE
(Dell Inc.) C:\Windows\System32\bcmwltry.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Dell Inc.) C:\Windows\System32\WLTRAY.EXE
(CyberLink Corp.) C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Macrovision Corporation) C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
() C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\BBSvc.EXE
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Ralink Technology, Corp.) C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\Service\RaRegistry.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Broadcom Corporation.) c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\HidFind.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apntex.exe
(Microsoft Corporation) C:\Windows\system32\conime.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [233472 2009-03-10] (Alps Electric Co., Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Windows\system32\WLTRAY.exe [3563520 2008-12-11] (Dell Inc.)
HKLM\...\Run: [Microsoft Default Manager] - C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [250192 2009-04-24] (Microsoft Corporation)
HKLM\...\Run: [PDVDDXSrv] - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe [128232 2009-02-05] (CyberLink Corp.)
HKLM\...\Run: [Dell Webcam Central] - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [405639 2009-01-09] (Creative Technology Ltd)
HKLM\...\Run: [MDS_Menu] - C:\Program Files\Olympus\ib\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-24] (Avira Operations GmbH & Co. KG)
HKLM\...\Run: [TkBellExe] - c:\program files\real\realplayer\Update\realsched.exe [295512 2013-10-24] (RealNetworks, Inc.)
HKU\S-1-5-19\...\Policies\Explorer: [NofolderOptions] 0
HKU\S-1-5-20\...\Policies\Explorer: [NofolderOptions] 0
HKU\S-1-5-21-3297751244-2427133805-2756156200-1000\...\Run: [ISUSPM] - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [218032 2006-09-11] (Macrovision Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Fixhomepage
URLSearchHook: HKCU - (No Name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - No File
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {B166D7A5-26D0-466D-BD7B-6BCCD458A5A3} URL = hxxp://www.bing.com/search?FORM=DLSDF7&q={searchTerms}&src={referrer:source?}&PC=MDDS
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldde-de.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 05 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 06 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 07 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 08 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Winsock: Catalog9 20 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [257608] (Avira Operations GmbH & Co. KG)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{33AB366A-82D7-4190-B97C-3622B7C19378}: [NameServer]4.2.2.4,4.2.2.5
FireFox:
========
FF ProfilePath: C:\Users\Wadija & Ibo\AppData\Roaming\Mozilla\Firefox\Profiles\hvu1rdbs.default
FF SearchEngineOrder.1: Ask.com
FF Homepage: hxxp://www.google.com/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @ma-config.com/HardwareDetection - C:\Program Files\ma-config.com\nphardwaredetection.dll (Cybelsoft)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.3.51 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.3 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.3.51 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: DownloadHelper - C:\Users\Wadija & Ibo\AppData\Roaming\Mozilla\Firefox\Profiles\hvu1rdbs.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-25]
FF Extension: Adblock Plus - C:\Users\Wadija & Ibo\AppData\Roaming\Mozilla\Firefox\Profiles\hvu1rdbs.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-13]
FF Extension: Watch Mode - C:\Users\Wadija & Ibo\AppData\Roaming\Mozilla\Firefox\Profiles\hvu1rdbs.default\Extensions\{f8d46537-88fa-41cd-9f4f-a47ba0346190}.xpi [2013-07-01]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2014-02-26]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: [{DF153AFF-6948-45d7-AC98-4FC4AF8A08E2}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-24] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1017424 2014-02-24] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2014-02-13] (APN LLC.)
S3 maconfservice; C:\Program Files\ma-config.com\maconfservice.exe [311960 2012-08-03] (CybelSoft)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-03-05] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-03-05] (Malwarebytes Corporation)
R2 RalinkRegistryWriter; C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\Service\RaRegistry.exe [375872 2011-12-26] (Ralink Technology, Corp.)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-08-14] ()
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2654208 2008-12-11] (Dell Inc.)
S2 otshot; C:\program files\otshot\ZalmanUpdateService.exe [X]
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-12-06] (Avira Operations GmbH & Co. KG)
R3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys [18424 2008-12-11] (Broadcom Corporation)
S3 driverhardwarev2; C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys [16640 2011-07-21] (CybelSoft)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-03-05] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [107736 2014-03-25] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51416 2014-03-05] (Malwarebytes Corporation)
R3 netr28u; C:\Windows\System32\DRIVERS\netr28u.sys [1093472 2012-02-14] (Ralink Technology Corp.)
R2 risdpcie; C:\Windows\System32\DRIVERS\risdpe86.sys [48640 2009-03-30] (REDC)
S4 rixdpcie; C:\Windows\system32\drivers\rixdpe86.sys [38400 2009-01-14] (REDC)
R1 RtlProt; C:\Windows\System32\DRIVERS\rtlprot.sys [25896 2007-04-23] (Windows (R) Codename Longhorn DDK provider)
R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-07] (Avira GmbH)
S3 usbbus; C:\Windows\System32\DRIVERS\lgusbbus.sys [13056 2008-11-11] (LG Electronics Inc.)
S3 UsbDiag; C:\Windows\System32\DRIVERS\lgusbdiag.sys [19968 2008-11-11] (LG Electronics Inc.)
S3 USBModem; C:\Windows\System32\DRIVERS\lgusbmodem.sys [24832 2008-11-11] (LG Electronics Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\Users\WADIJA~1\AppData\Local\Temp\catchme.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 RTL8192cu; system32\DRIVERS\RTL8192cu.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-25 19:07 - 2014-03-25 19:07 - 00016918 _____ () C:\Users\Wadija & Ibo\Desktop\FRST.txt
2014-03-25 18:14 - 2014-03-25 18:14 - 00000000 ____D () C:\Windows\ERUNT
2014-03-25 18:12 - 2014-03-25 18:13 - 01038974 _____ (Thisisu) C:\Users\Wadija & Ibo\Downloads\JRT.exe
2014-03-25 17:57 - 2014-03-25 17:57 - 00001059 _____ () C:\Users\Wadija & Ibo\Desktop\Revo Uninstaller.lnk
2014-03-25 17:57 - 2014-03-25 17:57 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-03-25 17:56 - 2014-03-25 17:56 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Wadija & Ibo\Downloads\revosetup95.exe
2014-03-25 17:49 - 2014-03-25 18:55 - 00000000 ____D () C:\AdwCleaner
2014-03-25 17:49 - 2014-03-25 17:49 - 01950720 _____ () C:\Users\Wadija & Ibo\Downloads\adwcleaner.exe
2014-03-25 17:15 - 2014-03-25 19:07 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-25 17:15 - 2014-03-25 17:15 - 00000901 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-25 17:14 - 2014-03-25 17:15 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-03-25 17:14 - 2014-03-25 17:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-25 17:14 - 2014-03-05 09:26 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-25 17:14 - 2014-03-05 09:26 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-25 17:14 - 2014-03-05 09:26 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-25 17:11 - 2014-03-25 17:12 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Wadija & Ibo\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-23 19:57 - 2014-03-23 19:57 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\Aqaed flash
2014-03-23 19:57 - 2014-03-23 19:57 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Roaming\Shetab
2014-03-23 13:26 - 2014-03-25 19:07 - 00000000 ____D () C:\FRST
2014-03-23 13:24 - 2014-03-23 13:24 - 01145856 _____ (Farbar) C:\Users\Wadija & Ibo\Desktop\FRST.exe
2014-03-23 11:49 - 2014-03-23 11:49 - 00012735 _____ () C:\ComboFix.txt
2014-03-23 11:35 - 2014-03-23 11:49 - 00000000 ____D () C:\Qoobox
2014-03-23 11:35 - 2014-03-23 11:49 - 00000000 ____D () C:\ComboFix
2014-03-23 11:35 - 2011-06-26 11:15 - 00256000 _____ () C:\Windows\PEV.exe
2014-03-23 11:35 - 2010-11-07 21:50 - 00208896 _____ () C:\Windows\MBR.exe
2014-03-23 11:35 - 2009-04-20 09:26 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-03-23 11:35 - 2000-08-31 04:30 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-03-23 11:35 - 2000-08-31 04:30 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-03-23 11:35 - 2000-08-31 04:30 - 00098816 _____ () C:\Windows\sed.exe
2014-03-23 11:35 - 2000-08-31 04:30 - 00080412 _____ () C:\Windows\grep.exe
2014-03-23 11:35 - 2000-08-31 04:30 - 00068096 _____ () C:\Windows\zip.exe
2014-03-23 11:34 - 2014-03-23 11:47 - 00000000 ____D () C:\Windows\erdnt
2014-03-23 11:24 - 2014-03-23 11:25 - 05190773 ____R (Swearware) C:\Users\Wadija & Ibo\Desktop\ComboFix.exe
2014-03-17 22:44 - 2014-02-23 10:20 - 12347904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-17 22:44 - 2014-02-23 10:17 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-17 22:44 - 2014-02-23 10:13 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-17 22:44 - 2014-02-23 10:11 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-17 22:44 - 2014-02-23 10:10 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-17 22:44 - 2014-02-23 10:09 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-17 22:44 - 2014-02-23 10:08 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-03-17 22:44 - 2014-02-23 10:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-17 22:44 - 2014-02-23 10:08 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-17 22:44 - 2014-02-23 10:07 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-17 22:44 - 2014-02-23 10:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-03-17 22:44 - 2014-02-23 10:07 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-17 22:44 - 2014-02-23 10:07 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-03-17 22:44 - 2014-02-23 10:06 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-17 22:44 - 2014-02-23 10:06 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-03-17 22:44 - 2014-02-23 10:05 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-17 19:12 - 2014-02-07 15:08 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-17 19:12 - 2014-02-03 15:07 - 00505344 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-17 19:11 - 2014-01-30 12:16 - 00876032 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-17 19:11 - 2013-11-13 05:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-03-06 18:26 - 2014-03-24 16:14 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\Aqaed Lehrbuch
2014-03-03 18:42 - 2014-03-14 18:39 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\ROS
2014-02-28 20:19 - 2014-02-28 20:22 - 03618233 _____ (Igor Pavlov) C:\Users\Wadija & Ibo\Downloads\D2SE_MiddleEarth_1.92_sfx.exe
2014-02-28 20:17 - 2014-02-28 20:17 - 00001041 _____ () C:\Users\Wadija & Ibo\Downloads\trade.d2s
2014-02-28 20:16 - 2014-02-28 20:16 - 00000918 _____ () C:\Users\Wadija & Ibo\Downloads\Xaver.d2s
2014-02-28 20:00 - 2014-02-28 21:03 - 79677717 _____ () C:\Users\Wadija & Ibo\Downloads\D2SE_RoS_083a_sfx.exe
2014-02-27 18:41 - 2014-02-27 18:41 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Roaming\Reallusion
2014-02-27 18:41 - 2014-02-27 18:41 - 00000000 ____D () C:\ProgramData\Creative
2014-02-27 16:47 - 2014-03-24 19:18 - 00002379 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-02-27 16:47 - 2014-02-27 16:47 - 00000000 ___RD () C:\Program Files\Skype
2014-02-27 16:47 - 2014-02-27 16:47 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Local\Skype
2014-02-27 16:47 - 2014-02-27 16:47 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-26 20:26 - 2014-02-26 20:26 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-24 20:08 - 2014-03-23 17:54 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\Tarix Übersetzung
2014-02-24 18:43 - 2013-12-05 06:42 - 01248768 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
==================== One Month Modified Files and Folders =======
2014-03-25 19:08 - 2014-03-25 19:07 - 00016918 _____ () C:\Users\Wadija & Ibo\Desktop\FRST.txt
2014-03-25 19:07 - 2014-03-25 17:15 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-03-25 19:07 - 2014-03-23 13:26 - 00000000 ____D () C:\FRST
2014-03-25 19:03 - 2008-01-21 12:51 - 01635868 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-25 18:59 - 2012-08-13 18:13 - 00000374 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-03-25 18:59 - 2006-11-02 17:15 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-25 18:59 - 2006-11-02 17:15 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-25 18:58 - 2011-08-05 14:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-03-25 18:57 - 2010-07-07 11:14 - 00065536 _____ () C:\Windows\system32\Ikeext.etl
2014-03-25 18:57 - 2006-11-02 17:28 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-25 18:56 - 2009-09-30 09:26 - 00001076 _____ () C:\Windows\bthservsdp.dat
2014-03-25 18:56 - 2009-09-30 09:24 - 01081713 _____ () C:\Windows\WindowsUpdate.log
2014-03-25 18:56 - 2006-11-02 17:28 - 00032562 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-25 18:55 - 2014-03-25 17:49 - 00000000 ____D () C:\AdwCleaner
2014-03-25 18:47 - 2012-07-05 11:07 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-25 18:41 - 2011-08-05 14:51 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-03-25 18:19 - 2006-11-02 15:48 - 00000000 ____D () C:\Windows\tracing
2014-03-25 18:17 - 2008-01-21 07:32 - 00241684 _____ () C:\Windows\PFRO.log
2014-03-25 18:14 - 2014-03-25 18:14 - 00000000 ____D () C:\Windows\ERUNT
2014-03-25 18:13 - 2014-03-25 18:12 - 01038974 _____ (Thisisu) C:\Users\Wadija & Ibo\Downloads\JRT.exe
2014-03-25 17:57 - 2014-03-25 17:57 - 00001059 _____ () C:\Users\Wadija & Ibo\Desktop\Revo Uninstaller.lnk
2014-03-25 17:57 - 2014-03-25 17:57 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-03-25 17:56 - 2014-03-25 17:56 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Wadija & Ibo\Downloads\revosetup95.exe
2014-03-25 17:49 - 2014-03-25 17:49 - 01950720 _____ () C:\Users\Wadija & Ibo\Downloads\adwcleaner.exe
2014-03-25 17:15 - 2014-03-25 17:15 - 00000901 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-03-25 17:15 - 2014-03-25 17:14 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-03-25 17:14 - 2014-03-25 17:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-03-25 17:12 - 2014-03-25 17:11 - 17523384 _____ (Malwarebytes Corporation ) C:\Users\Wadija & Ibo\Downloads\mbam-setup-2.0.0.1000.exe
2014-03-24 21:14 - 2013-09-20 20:33 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Roaming\Skype
2014-03-24 19:18 - 2014-02-27 16:47 - 00002379 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-03-24 16:14 - 2014-03-06 18:26 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\Aqaed Lehrbuch
2014-03-23 19:57 - 2014-03-23 19:57 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\Aqaed flash
2014-03-23 19:57 - 2014-03-23 19:57 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Roaming\Shetab
2014-03-23 19:56 - 2012-08-06 11:41 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Local\Adobe
2014-03-23 19:56 - 2012-08-06 11:38 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-23 17:54 - 2014-02-24 20:08 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\Tarix Übersetzung
2014-03-23 13:24 - 2014-03-23 13:24 - 01145856 _____ (Farbar) C:\Users\Wadija & Ibo\Desktop\FRST.exe
2014-03-23 11:49 - 2014-03-23 11:49 - 00012735 _____ () C:\ComboFix.txt
2014-03-23 11:49 - 2014-03-23 11:35 - 00000000 ____D () C:\Qoobox
2014-03-23 11:49 - 2014-03-23 11:35 - 00000000 ____D () C:\ComboFix
2014-03-23 11:49 - 2006-11-02 15:48 - 00000000 __RHD () C:\Users\Default
2014-03-23 11:49 - 2006-11-02 15:48 - 00000000 ___RD () C:\Users\Public
2014-03-23 11:47 - 2014-03-23 11:34 - 00000000 ____D () C:\Windows\erdnt
2014-03-23 11:46 - 2006-11-02 14:53 - 00000215 _____ () C:\Windows\system.ini
2014-03-23 11:25 - 2014-03-23 11:24 - 05190773 ____R (Swearware) C:\Users\Wadija & Ibo\Desktop\ComboFix.exe
2014-03-22 07:33 - 2013-10-24 17:28 - 00000600 _____ () C:\Users\Wadija & Ibo\AppData\Local\PUTTY.RND
2014-03-19 18:47 - 2013-07-23 16:19 - 00000000 ____D () C:\Windows\system32\MRT
2014-03-19 18:45 - 2006-11-02 14:54 - 87350280 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-03-18 18:32 - 2006-11-02 15:48 - 00000000 ____D () C:\Windows\rescache
2014-03-18 18:07 - 2006-11-02 17:14 - 00249512 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-18 18:05 - 2009-09-30 15:01 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-03-17 22:43 - 2006-11-02 15:48 - 00000000 ____D () C:\Windows\system32\de-DE
2014-03-15 20:37 - 2013-11-08 14:05 - 01078608 _____ () C:\Users\Wadija & Ibo\Downloads\psiphon3.exe
2014-03-14 18:39 - 2014-03-03 18:42 - 00000000 ____D () C:\Users\Wadija & Ibo\Documents\ROS
2014-03-08 21:07 - 2013-11-08 14:05 - 01072976 _____ () C:\Users\Wadija & Ibo\Downloads\psiphon3.exe.orig
2014-03-06 20:11 - 2013-06-16 18:40 - 00000000 ____D () C:\Program Files\Diablo II
2014-03-05 09:26 - 2014-03-25 17:14 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-03-05 09:26 - 2014-03-25 17:14 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-03-05 09:26 - 2014-03-25 17:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-03-04 20:27 - 2013-07-20 17:35 - 00000000 ____D () C:\Users\Wadija & Ibo\Desktop\Duping
2014-03-03 23:00 - 2006-11-02 15:48 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-02-28 21:03 - 2014-02-28 20:00 - 79677717 _____ () C:\Users\Wadija & Ibo\Downloads\D2SE_RoS_083a_sfx.exe
2014-02-28 20:22 - 2014-02-28 20:19 - 03618233 _____ (Igor Pavlov) C:\Users\Wadija & Ibo\Downloads\D2SE_MiddleEarth_1.92_sfx.exe
2014-02-28 20:17 - 2014-02-28 20:17 - 00001041 _____ () C:\Users\Wadija & Ibo\Downloads\trade.d2s
2014-02-28 20:16 - 2014-02-28 20:16 - 00000918 _____ () C:\Users\Wadija & Ibo\Downloads\Xaver.d2s
2014-02-27 18:41 - 2014-02-27 18:41 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Roaming\Reallusion
2014-02-27 18:41 - 2014-02-27 18:41 - 00000000 ____D () C:\ProgramData\Creative
2014-02-27 18:00 - 2012-08-09 10:23 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-02-27 16:47 - 2014-02-27 16:47 - 00000000 ___RD () C:\Program Files\Skype
2014-02-27 16:47 - 2014-02-27 16:47 - 00000000 ____D () C:\Users\Wadija & Ibo\AppData\Local\Skype
2014-02-27 16:47 - 2014-02-27 16:47 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-02-27 16:47 - 2013-09-20 20:32 - 00000000 ____D () C:\ProgramData\Skype
2014-02-26 20:26 - 2014-02-26 20:26 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-02-23 10:20 - 2014-03-17 22:44 - 12347904 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-23 10:17 - 2014-03-17 22:44 - 01806848 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-23 10:13 - 2014-03-17 22:44 - 09739264 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-23 10:11 - 2014-03-17 22:44 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-23 10:10 - 2014-03-17 22:44 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-23 10:09 - 2014-03-17 22:44 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-23 10:08 - 2014-03-17 22:44 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-02-23 10:08 - 2014-03-17 22:44 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-23 10:08 - 2014-03-17 22:44 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-23 10:07 - 2014-03-17 22:44 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-23 10:07 - 2014-03-17 22:44 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-02-23 10:07 - 2014-03-17 22:44 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-23 10:07 - 2014-03-17 22:44 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-23 10:06 - 2014-03-17 22:44 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-23 10:06 - 2014-03-17 22:44 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-02-23 10:05 - 2014-03-17 22:44 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
Files to move or delete:
====================
C:\Users\Wadija & Ibo\AppData\Roaming\desktop.ini
Some content of TEMP:
====================
C:\Users\Wadija & Ibo\AppData\Local\temp\avgnt.exe
C:\Users\Wadija & Ibo\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-25 19:06
==================== End Of Log ============================
--- --- ---
--- --- ---