Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 16.10.2014
Scan Time: 19:28:12
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.3.1025
Malware Database: v2014.10.16.05
Rootkit Database: v2014.10.15.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: User
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 315957
Time Elapsed: 10 min, 58 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 1
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\EZ Software Updater.exe, 1704, Delete-on-Reboot, [bda816ff047864d2ac9b31e91ce7dc24]
Modules: 0
(No malicious items detected)
Registry Keys: 6
PUP.Optional.EZSoftware.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EZ Software Updater, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\EZ Software Updater_is1, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, HKLM\SOFTWARE\WOW6432NODE\EZ Software Updater, Quarantined, [d88d17fe0b718da91830b46638cbae52],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-3012146909-3591809443-1932921972-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Conduit_Search_Protect, Delete-on-Reboot, [7aeba471df9da98dea86553044c0e11f],
PUP.Optional.DVDVideoSoftTB.A, HKU\S-1-5-21-3012146909-3591809443-1932921972-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\nikpibnbobmbdbheedjfogjlikpgpnhp, Delete-on-Reboot, [df862ee7a8d450e63ceca17b34cf1ee2],
PUP.Optional.VideoPerformer.A, HKU\S-1-5-21-3012146909-3591809443-1932921972-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\PERFORMERSOFT LLC\Video Performer, Delete-on-Reboot, [f471e82d5b213cfa05018b9f56ad2bd5],
Registry Values: 0
(No malicious items detected)
Registry Data: 1
PUP.Optional.Conduit.A, HKU\S-1-5-21-3012146909-3591809443-1932921972-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://search.conduit.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=MD232EF6F-C3B6-4BD8-BFAC-919A03807557&SearchSource=55&CUI=&UM=5&UP=SPE57231B6-3884-4564-9940-5CEE71EE5BB8&SSPV=, Good: (www.google.com), Bad: (hxxp://search.conduit.com/?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=MD232EF6F-C3B6-4BD8-BFAC-919A03807557&SearchSource=55&CUI=&UM=5&UP=SPE57231B6-3884-4564-9940-5CEE71EE5BB8&SSPV=),Delete-on-Reboot,[ff66eb2a007c0d290d9ce434eb1a867a]
Folders: 10
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater, Delete-on-Reboot, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\lib, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\temp, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\update, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\0F8C710D7E384D7698E449335364B5FE, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\31FA7C942BE84FFD966E964F0A498FB0, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\5E13F44AD05A436792145791E6F1F434, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\6BE761A9495C4980A5641F20E9708F0F, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\929E5C572A354A2183C52FE8C28E2F22, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
Files: 21
PUP.Optional.Conduit.A, C:\Users\User\AppData\Roaming\OpenCandy\5E13F44AD05A436792145791E6F1F434\search_protect_global.exe, Quarantined, [1f468a8b7efe4ee802081e1330d17888],
PUP.Optional.Somoto, C:\Users\User\Downloads\etypesetup.exe, Quarantined, [5b0a47ce99e3d0660b018fb833d209f7],
PUP.Optional.Domalq, C:\Users\User\Downloads\Java.exe, Quarantined, [78ed779eeb91b58135a166de36cad62a],
PUP.Optional.DomalQ, C:\Users\User\Downloads\Java (1).exe, Quarantined, [00659e77166684b2676b4cb1fb09f50b],
PUP.Optional.DomalQ, C:\Users\User\Downloads\Java (2).exe, Quarantined, [9fc63ed70676033300d289745aaa14ec],
PUP.Optional.DomalQ, C:\Users\User\Downloads\Java (3).exe, Quarantined, [20459d789ce095a1e8ea28d5a85c6898],
PUP.Optional.Bundlore, C:\Users\User\Downloads\Setup.exe, Quarantined, [7de8c352512b61d5311c7e8cee1726da],
PUP.Optional.Bandoo, C:\Users\User\Downloads\jZipSetup-r0-n-bc.exe, Quarantined, [263f789d314bf046c66ff0dcfb06916f],
Adware.InstallBrain, C:\Users\User\Downloads\VideoPerformerSetup.exe, Quarantined, [0560b065324a0d29aadad6987190ba46],
Trojan.Ransom.RRE, C:\Users\User\Downloads\video_HD.zip, Quarantined, [6302e530116b3afca8694ab3ec14b44c],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\unins000.dat, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\cfg.ini, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\EZ Software Updater.exe, Delete-on-Reboot, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\unins000.exe, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\updateStatus.ini, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\lib\EZ Software Updater.dll, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\temp\response.ini, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.EZSoftware.A, C:\Program Files (x86)\EZ Software Updater\temp\update.ini, Quarantined, [bda816ff047864d2ac9b31e91ce7dc24],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\31FA7C942BE84FFD966E964F0A498FB0\TuneUpUtilities2012_de-DE.exe, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\6BE761A9495C4980A5641F20E9708F0F\TuneUpUtilities2014_de-DE.exe, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
PUP.Optional.OpenCandy, C:\Users\User\AppData\Roaming\OpenCandy\929E5C572A354A2183C52FE8C28E2F22\TuneUpUtilities2013_2200218_de-DE.exe, Quarantined, [94d130e5a2dab4828c7ad417f70b758b],
Physical Sectors: 0
(No malicious items detected)
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v4.000 - Bericht erstellt am 16/10/2014 um 19:53:01
# DB v2014-10-15.7
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : User - USER-PC
# Gestartet von : C:\Users\User\Downloads\AdwCleaner_4.000.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\Common Files\DVDVideoSoft\TB
Ordner Gelöscht : C:\Users\User\AppData\Roaming\dvdvideosoftiehelpers
Ordner Gelöscht : C:\Program Files (x86)\jZip
Ordner Gelöscht : C:\Users\User\AppData\Local\jZip
Ordner Gelöscht : C:\Users\User\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\User\AppData\Roaming\RHEng
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{22222222-2222-2222-2222-220022502260}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055505560}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066506660}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55555555-5555-5555-5555-550055505560}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66666666-6666-6666-6666-660066506660}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\jZip
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\performersoft llc
Schlüssel Gelöscht : HKCU\Software\torch
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\torch
Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
-\\ Google Chrome v
Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?gd=&ctid=CT3321540&octid=EB_ORIGINAL_CTID&ISID=MD232EF6F-C3B6-4BD8-BFAC-919A03807557&SearchSource=58&CUI=&UM=5&UP=SPE57231B6-3884-4564-9940-5CEE71EE5BB8&q={searchTerms}&SSPV=
*************************
AdwCleaner[R0].txt - [4981 octets] - [16/10/2014 19:49:54]
AdwCleaner[S0].txt - [4733 octets] - [16/10/2014 19:53:01]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4793 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 7 Professional x64
Ran by User on 16.10.2014 at 19:59:21,57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011501160}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011501160}
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.10.2014 at 20:06:04,64
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by User (administrator) on USER-PC on 16-10-2014 20:07:31
Running from C:\Users\User\Downloads
Loaded Profile: User (Available profiles: User)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Lenovo) C:\Windows\System32\ibmpmsvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Apple Inc.) C:\Users\User\Desktop\Free YouTube to MP3 Converter\iTunesHelper.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\User\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-11-02] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Users\User\Desktop\Free YouTube to MP3 Converter\iTunesHelper.exe [421736 2012-01-16] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-01-30] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-09] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [165168 2014-09-23] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3012146909-3591809443-1932921972-1000\...\Run: [GoogleChromeAutoLaunch_BCEA24321E5E4F1401136BBEDFB545FE] => C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe [852808 2014-09-23] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x781358931B1DCE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Users\User\Desktop\Free YouTube to MP3 Converter\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @java.com/DTPlugin,version=10.21.2 -> C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\User\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 -> C:\Users\User\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-03-02]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\ff [2014-04-26]
Chrome:
=======
CHR HomePage: Default -> hxxp://google.de/
CHR StartupUrls: Default -> "hxxp://google.de/"
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-05]
CHR Extension: (Google Wallet) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-07]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2013-03-03]
CHR HKLM-x32\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-02-07]
CHR StartMenuInternet: Google Chrome - C:\Users\User\AppData\Local\Google\Chrome\Application\chrome.exe
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-10-09] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-09] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-09] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160560 2014-09-23] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-09] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [37392 2010-05-20] (Paragon Software Group)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-10-16] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-10-01] (Malwarebytes Corporation)
S3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [33048 2006-11-30] (X10 Wireless Technology, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-16 20:07 - 2014-10-16 20:07 - 02112000 _____ (Farbar) C:\Users\User\Downloads\FRST64 (1).exe
2014-10-16 20:06 - 2014-10-16 20:06 - 00000940 _____ () C:\Users\User\Desktop\JRT.txt
2014-10-16 19:59 - 2014-10-16 19:59 - 00000000 ____D () C:\Windows\ERUNT
2014-10-16 19:58 - 2014-10-16 19:58 - 01705698 _____ (Thisisu) C:\Users\User\Downloads\JRT.exe
2014-10-16 19:49 - 2014-10-16 19:53 - 00000000 ____D () C:\AdwCleaner
2014-10-16 19:49 - 2014-10-16 19:49 - 01976320 _____ () C:\Users\User\Downloads\AdwCleaner_4.000.exe
2014-10-16 19:47 - 2014-10-16 19:47 - 00007012 _____ () C:\Users\User\Desktop\mbam.txt
2014-10-16 19:27 - 2014-10-16 19:57 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-16 19:26 - 2014-10-16 19:26 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-10-16 19:26 - 2014-10-16 19:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-10-16 19:26 - 2014-10-16 19:26 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-10-16 19:26 - 2014-10-16 19:26 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-10-16 19:26 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-16 19:26 - 2014-10-01 11:11 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-16 19:26 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-10-16 19:25 - 2014-10-16 19:25 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\User\Downloads\mbam-setup-2.0.3.1025.exe
2014-10-15 23:32 - 2014-10-15 23:32 - 00018055 _____ () C:\ComboFix.txt
2014-10-15 23:09 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-15 23:09 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-15 23:09 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-15 23:09 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-15 23:09 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-15 23:09 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-15 23:09 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-15 23:09 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-15 23:00 - 2014-10-15 23:01 - 05583559 ____R (Swearware) C:\Users\User\Desktop\ComboFix.exe
2014-10-15 22:58 - 2014-10-15 22:59 - 05583559 _____ (Swearware) C:\Users\User\Downloads\ComboFix (1).exe
2014-10-15 22:56 - 2014-10-15 23:32 - 00000000 ____D () C:\Qoobox
2014-10-15 22:55 - 2014-10-15 23:29 - 00000000 ____D () C:\Windows\erdnt
2014-10-15 22:54 - 2014-10-15 22:55 - 05583559 ____R (Swearware) C:\Users\User\Downloads\ComboFix.exe
2014-10-15 22:39 - 2014-10-15 22:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\User\Downloads\revosetup95.exe
2014-10-15 22:39 - 2014-10-15 22:39 - 00001275 _____ () C:\Users\User\Desktop\Revo Uninstaller.lnk
2014-10-15 22:39 - 2014-10-15 22:39 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-10-14 22:37 - 2014-10-14 22:38 - 00020436 _____ () C:\Users\User\Downloads\Addition.txt
2014-10-14 22:36 - 2014-10-16 20:07 - 00012155 _____ () C:\Users\User\Downloads\FRST.txt
2014-10-14 22:36 - 2014-10-16 20:07 - 00000000 ____D () C:\FRST
2014-10-14 22:35 - 2014-10-14 22:36 - 02110464 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2014-10-14 21:55 - 2014-10-14 21:56 - 00000000 ____D () C:\Users\User\Documents\sammel
2014-10-14 20:02 - 2014-10-14 20:02 - 00001140 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-10-11 16:41 - 2014-10-12 14:55 - 00015491 _____ () C:\Users\User\Desktop\lps.ods
2014-10-11 13:05 - 2014-10-11 13:16 - 00000000 ____D () C:\Users\User\Desktop\Cannes und St Tropez Buch
2014-10-10 12:22 - 2014-10-13 19:56 - 00000051 _____ () C:\Users\User\Desktop\songs.txt
2014-10-09 14:29 - 2014-10-11 12:11 - 390125584 _____ () C:\Users\User\Desktop\2013.cpr
2014-10-09 14:06 - 2014-10-09 14:09 - 272003744 _____ () C:\Users\User\Downloads\ALDI_Bestellsoftware_Setup (1).exe
2014-10-09 12:36 - 2014-10-09 12:36 - 00858418 _____ () C:\Users\User\Downloads\2000-005-de.zip
2014-10-08 12:15 - 2014-10-08 12:15 - 00183843 _____ () C:\Users\User\Downloads\Williams_1971_Jackpot_Reproduction_Score_and_Instruction_Cards.zip
2014-09-30 19:25 - 2014-09-25 04:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-30 19:25 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-23 22:24 - 2014-09-10 00:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-23 22:24 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-16 20:03 - 2009-07-14 06:45 - 00021504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-16 20:03 - 2009-07-14 06:45 - 00021504 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-16 19:54 - 2010-11-21 05:47 - 00215864 _____ () C:\Windows\PFRO.log
2014-10-16 19:54 - 2009-07-14 06:51 - 00103349 _____ () C:\Windows\setupact.log
2014-10-16 19:53 - 2012-01-09 17:22 - 01634981 _____ () C:\Windows\WindowsUpdate.log
2014-10-16 19:41 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PLA
2014-10-15 23:23 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-10-14 22:44 - 2013-09-06 19:10 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-14 22:44 - 2012-06-07 08:55 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-14 22:13 - 2014-04-23 18:43 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-14 22:13 - 2012-01-29 19:21 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-10-14 22:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-14 22:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-10-14 22:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
2014-10-14 22:11 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-10-14 20:02 - 2014-08-30 12:40 - 00000000 ____D () C:\ProgramData\Package Cache
2014-10-14 20:02 - 2013-08-09 19:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-10-14 20:01 - 2013-08-09 19:06 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-10-11 13:21 - 2011-04-12 09:43 - 00699682 _____ () C:\Windows\system32\perfh007.dat
2014-10-11 13:21 - 2011-04-12 09:43 - 00149790 _____ () C:\Windows\system32\perfc007.dat
2014-10-11 13:21 - 2009-07-14 07:13 - 01620684 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-10-09 11:29 - 2013-08-09 19:08 - 00043064 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-10-09 11:29 - 2013-08-09 19:06 - 00131608 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-10-09 11:29 - 2013-08-09 19:06 - 00119272 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-10-05 19:04 - 2014-02-23 21:49 - 00000000 ____D () C:\Users\User\Desktop\sammel
Some content of TEMP:
====================
C:\Users\User\AppData\Local\Temp\avgnt.exe
C:\Users\User\AppData\Local\Temp\Quarantine.exe
C:\Users\User\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2013-08-02 19:42
==================== End Of Log ============================
--- --- ---
--- --- ---