Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 18.03.2015
Suchlauf-Zeit: 22:00:30
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2014.11.20.06
Rootkit Datenbank: v2014.11.18.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Joschi
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 353209
Verstrichene Zeit: 24 Min, 8 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 5
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\awesomehp Browser newtab extension, In Quarantäne, [7393c37b1d5ff83e7c52fc766d968b75],
PUP.Optional.Awesomehp.A, HKLM\SOFTWARE\WOW6432NODE\awesomehpSoftware, In Quarantäne, [16f052ecde9e85b1c929234fbd46a25e],
PUP.Optional.Feven.A, HKLM\SOFTWARE\WOW6432NODE\Feven Pro, In Quarantäne, [51b5023ce19beb4b8cf39cd437cc4fb1],
PUP.Optional.Feven.A, HKU\S-1-5-21-3714319823-260000009-872883684-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\APPDATALOW\SOFTWARE\Feven Pro, Löschen bei Neustart, [9d69ec5278049a9c0875b2be08fb36ca],
PUP.Optional.ReMarkit.A, HKU\S-1-5-21-3714319823-260000009-872883684-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\APPDATALOW\SOFTWARE\Re_markit, Löschen bei Neustart, [709682bcf28a1e18e37ffd438083be42],
Registrierungswerte: 1
PUM.Bad.Proxy, HKU\S-1-5-21-3714319823-260000009-872883684-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-1\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|ProxyServer, http=127.0.0.1:13828, Löschen bei Neustart, [5fa7df5f443869cd43727430ab5929d7]
Registrierungsdaten: 1
PUP.Optional.Qone8, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES|DefaultScope, {33BB0A4E-99AF-4226-BDF6-49120163DE86}, Gut: ({0633EE93-D776-472f-A0FF-E1416B8B2E3A}), Schlecht: ({33BB0A4E-99AF-4226-BDF6-49120163DE86}),Ersetzt,[699d69d52557eb4b71a21a35ce37f907]
Ordner: 1
PUP.Optional.Awesomehp.A, C:\Users\Joschi\AppData\Roaming\awesomehp, In Quarantäne, [7393c37b1d5ff83e7c52fc766d968b75],
Dateien: 9
PUP.Optional.SkyTech.A, C:\Users\Joschi\AppData\Roaming\awesomehp\QQBrowserFrame.dll, In Quarantäne, [9175390592ea162057f83ef42fd1fc04],
PUP.Optional.AdvancedSystemProtector, C:\Windows\System32\sasnative64.exe, In Quarantäne, [53b368d6c2baa096fe70e3d437ca0ef2],
PUP.Optional.VOPackage.A, C:\Users\Joschi\AppData\Local\Temp\~nsu.tmp\Au_.exe, In Quarantäne, [8581d668275513236f9dc98abf4157a9],
PUP.Optional.DomalQ, C:\Users\Joschi\Downloads\Java.exe, In Quarantäne, [d432ba84e795ef470df940cb47beaa56],
PUP.Optional.BundleInstaller.A, C:\Users\Joschi\Downloads\setup.exe, In Quarantäne, [c640ef4f0b713bfbffad8dd257aa11ef],
PUP.Optional.Awesomehp.A, C:\Users\Joschi\AppData\Roaming\awesomehp\54.json, In Quarantäne, [7393c37b1d5ff83e7c52fc766d968b75],
PUP.Optional.Awesomehp.A, C:\Users\Joschi\AppData\Roaming\awesomehp\awesomehp.exe, In Quarantäne, [7393c37b1d5ff83e7c52fc766d968b75],
PUP.Optional.Awesomehp.A, C:\Users\Joschi\AppData\Roaming\awesomehp\DataBase, In Quarantäne, [7393c37b1d5ff83e7c52fc766d968b75],
PUP.Optional.Awesomehp.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\awesomehp.xml, In Quarantäne, [4bbb16281963e155953ae78be122847c],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 18.03.2015 21:59:44, SYSTEM, POU, Protection, Malware Protection, Starting,
Protection, 18.03.2015 21:59:44, SYSTEM, POU, Protection, Malware Protection, Started,
Protection, 18.03.2015 21:59:44, SYSTEM, POU, Protection, Malicious Website Protection, Starting,
Protection, 18.03.2015 21:59:44, SYSTEM, POU, Protection, Malicious Website Protection, Started,
Update, 18.03.2015 22:00:34, SYSTEM, POU, Manual, Remediation Database, 2013.10.16.1, 2015.3.9.1,
Error, 18.03.2015 22:02:38, SYSTEM, POU, Manual, 0,
Update, 18.03.2015 22:02:38, SYSTEM, POU, Manual, Rootkit Database, Failed, Unable to access update server, 2014.11.18.1, 2015.2.25.1,
Scan, 18.03.2015 22:29:17, SYSTEM, POU, Manual, Start: % 1 "% 2", Dauer: % 1 min 24 Sekunden, Bedrohungs-Suchlauf, Abgeschlossen, 0 Malwareerkennung, 17-Malwareerkennung,
Error, 18.03.2015 22:29:32, SYSTEM, POU, Manual, 0,
Error, 18.03.2015 22:29:32, SYSTEM, POU, Manual, 0,
Protection, 18.03.2015 22:32:38, SYSTEM, POU, Protection, Malware Protection, Starting,
Protection, 18.03.2015 22:32:39, SYSTEM, POU, Protection, Malware Protection, Started,
Protection, 18.03.2015 22:32:39, SYSTEM, POU, Protection, Malicious Website Protection, Starting,
Protection, 18.03.2015 22:34:03, SYSTEM, POU, Protection, Malicious Website Protection, Started,
Update, 18.03.2015 22:42:41, SYSTEM, POU, Scheduler, Rootkit Database, 2014.11.18.1, 2015.2.25.1,
(end) Code:
# AdwCleaner v3.019 - Bericht erstellt am 18/03/2015 um 23:11:29
# Aktualisiert 17/02/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Joschi - POU
# Gestartet von : C:\Users\Joschi\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.17183
-\\ Mozilla Firefox v36.0.1 (x86 de)
[ Datei : C:\Users\Joschi\AppData\Roaming\Mozilla\Firefox\Profiles\t6ma2sc2.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [13771 octets] - [18/02/2014 00:43:26]
AdwCleaner[R1].txt - [904 octets] - [18/03/2015 22:56:51]
AdwCleaner[R2].txt - [963 octets] - [18/03/2015 23:10:49]
AdwCleaner[S0].txt - [11324 octets] - [18/02/2014 00:44:06]
AdwCleaner[S1].txt - [885 octets] - [18/03/2015 23:11:29]
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [944 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.5 (03.17.2015:1)
OS: Windows 8 x64
Ran by Joschi on 18.03.2015 at 23:23:17,98
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\update whilokii
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\util whilokii
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateWhilokii_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\updateWhilokii_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilWhilokii_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\utilWhilokii_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateWhilokii_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\updateWhilokii_RASMANCS
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilWhilokii_RASAPI32
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\utilWhilokii_RASMANCS
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Joschi\AppData\Roaming\mozilla\firefox\profiles\t6ma2sc2.default\prefs.js
user_pref("browser.search.defaultengine", "Ask.com");
user_pref("browser.search.order.1", "Ask.com");
Emptied folder: C:\Users\Joschi\AppData\Roaming\mozilla\firefox\profiles\t6ma2sc2.default\minidumps [13 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 18.03.2015 at 23:26:44,91
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Joschi (administrator) on POU on 18-03-2015 23:58:20
Running from C:\Users\Joschi\Downloads
Loaded Profiles: Joschi (Available profiles: Joschi & Administrator)
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Online Games Manager\ogmservice.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
() C:\Program Files (x86)\Mobile Partner\Mobile Partner.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Farbar) C:\Users\Joschi\Downloads\FRST64(3).exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ASUSQuickGesture(x86)] => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe [20352 2012-09-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [ASUSTPLoader(x64)] => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe [169856 2012-09-11] (AsusTek)
HKLM\...\Run: [ASUSQuickGesture(x64)] => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe [22400 2012-09-11] (ASUSTeK Computer Inc.)
HKLM\...\Run: [ACMON] => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [107192 2012-08-24] (ASUS)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [5264016 2012-08-16] (VIA)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\AsusWSPanel.exe [3417984 2012-08-28] (ASUS Cloud Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2015-01-21] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [601928 2013-08-07] (BlueStack Systems, Inc.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [127792 2015-02-12] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3714319823-260000009-872883684-1001\...\MountPoints2: {3afa1282-35d9-11e3-8034-08606e4af0d0} - "F:\AutoRun.exe"
HKU\S-1-5-21-3714319823-260000009-872883684-1001\...\MountPoints2: {3afa12cd-35d9-11e3-8034-08606e4af0d0} - "F:\AutoRun.exe"
HKU\S-1-5-21-3714319823-260000009-872883684-1001\...\MountPoints2: {f83a432c-35dc-11e3-8035-001e101fb2d1} - "F:\AutoRun.exe"
HKU\S-1-5-21-3714319823-260000009-872883684-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [898048 2012-07-26] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk
ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe (ASUSTeK Computer Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.9.120\ASUSWSShellExt64.dll (ASUS Cloud Corporation.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-3714319823-260000009-872883684-1001] => Internet Explorer proxy is enabled.
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope value is missing.
SearchScopes: HKU\S-1-5-21-3714319823-260000009-872883684-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ASUS Browser Extension x64 -> {78234974-0C4B-4111-BDEB-D9A104418772} -> C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x64\BrowserExtension64.dll [2012-09-11] (ASUSTeK Computer Inc.)
BHO-x32: ASUS Browser Extension x86 -> {78234974-0C4B-4111-BDEB-D9A104418771} -> C:\Program Files (x86)\ASUS\ASUS Smart Gesture\install\x86\BrowserExtension.dll [2012-09-11] (ASUSTeK Computer Inc.)
Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation)
Tcpip\..\Interfaces\{3C2D7332-A7C1-4F97-8147-E75AFF9BA2B1}: [NameServer] 193.189.244.206 193.189.244.225
FireFox:
========
FF ProfilePath: C:\Users\Joschi\AppData\Roaming\Mozilla\Firefox\Profiles\t6ma2sc2.default
FF NewTab: chrome://lightning/content/newtab.html
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-04] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-04] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-12-21] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3714319823-260000009-872883684-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Joschi\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-05-07] (Unity Technologies ApS)
FF Extension: Avira Browser Safety - C:\Users\Joschi\AppData\Roaming\Mozilla\Firefox\Profiles\t6ma2sc2.default\Extensions\abs@avira.com [2015-03-09]
FF Extension: ep - C:\Users\Joschi\AppData\Roaming\Mozilla\Firefox\Profiles\t6ma2sc2.default\Extensions\jid1-0xtMKhXFEs4jIg@jetpack.xpi [2014-02-20]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2015-01-21] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2015-01-21] (Avira Operations GmbH & Co. KG)
R2 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [184056 2015-02-12] (Avira Operations GmbH & Co. KG)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [393032 2013-08-07] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [384840 2013-08-07] (BlueStack Systems, Inc.)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [129856 2012-06-27] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
S2 Mobile Partner. RunOuc; C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe [246112 2013-10-15] ()
R2 ogmservice; C:\Program Files (x86)\Online Games Manager\ogmservice.exe [581568 2014-03-27] (RealNetworks, Inc.)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27792 2012-08-14] (VIA Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16032 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [56704 2012-09-11] (ASUS Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2015-01-21] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [131608 2015-01-21] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-11-26] (Avira Operations GmbH & Co. KG)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [70984 2013-08-07] (BlueStack Systems)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-03-18] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
U0 msahci; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-18 23:26 - 2015-03-18 23:26 - 00002136 _____ () C:\Users\Joschi\Desktop\JRT.txt
2015-03-18 23:18 - 2015-03-18 23:22 - 01388672 _____ (Thisisu) C:\Users\Joschi\Downloads\JRT(3).exe
2015-03-18 23:02 - 2015-03-18 23:07 - 02171392 _____ () C:\Users\Joschi\Downloads\AdwCleaner_4.112(1).exe
2015-03-18 22:45 - 2015-03-18 22:45 - 00003682 _____ () C:\mbam.txt
2015-03-18 22:45 - 2015-03-18 22:45 - 00001488 _____ () C:\mbam.txt2.txt
2015-03-18 21:59 - 2015-03-18 21:59 - 00001104 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-03-18 21:59 - 2015-03-18 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-03-18 21:59 - 2015-03-18 21:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-03-18 21:59 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-03-18 21:59 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-03-18 15:44 - 2015-03-18 21:58 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Joschi\Downloads\mbam-setup-2.0.4.1028.exe
2015-03-18 12:46 - 2015-03-18 12:46 - 00001266 _____ () C:\Users\Joschi\Desktop\Revo Uninstaller.lnk
2015-03-18 12:46 - 2015-03-18 12:46 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-03-18 12:39 - 2015-03-18 12:45 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Joschi\Downloads\revosetup95(1).exe
2015-03-18 12:26 - 2015-03-18 12:36 - 02304936 _____ (VS Revo Group Ltd.) C:\Users\Joschi\Downloads\revosetup95.exe
2015-03-17 21:26 - 2015-03-17 21:26 - 00002080 _____ () C:\Users\Public\Desktop\Zoo Tycoon.lnk
2015-03-17 21:26 - 2015-03-17 21:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-03-17 21:22 - 2015-03-17 21:22 - 00000000 ____D () C:\Program Files (x86)\Microsoft Games
2015-03-17 17:01 - 2015-03-17 17:01 - 00002390 _____ () C:\Users\Public\Desktop\Spiel Dark Tales - Der Mord in der Rue Morgue von Edgar Allan Poe.lnk
2015-03-17 17:00 - 2015-03-17 17:01 - 00000000 ____D () C:\Program Files (x86)\Dark Tales - Der Mord in der Rue Morgue von Edgar Allan Poe
2015-03-17 17:00 - 2015-03-17 17:00 - 00000000 ____D () C:\Users\Joschi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dark Tales - Der Mord in der Rue Morgue von Edgar Allan Poe
2015-03-17 17:00 - 2015-03-17 17:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dark Tales - Der Mord in der Rue Morgue von Edgar Allan Poe
2015-03-17 11:23 - 2015-03-17 11:29 - 02095616 _____ (Farbar) C:\Users\Joschi\Downloads\FRST64(3).exe
2015-03-17 11:19 - 2015-03-17 11:22 - 01135104 _____ (Farbar) C:\Users\Joschi\Downloads\FRST(1).exe
2015-03-16 23:06 - 2015-03-18 22:34 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-03-16 22:41 - 2015-03-16 23:05 - 16502728 _____ (Malwarebytes Corp.) C:\Users\Joschi\Downloads\mbar-1.09.1.1004.exe
2015-03-06 13:53 - 2015-03-06 13:54 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-06 11:03 - 2015-03-06 11:03 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2015-03-01 11:02 - 2015-03-01 11:02 - 01055936 _____ (Adobe) C:\Users\Joschi\Downloads\install_flashplayer16x32_ltr5x64d_awc_aih(1).exe
2015-03-01 10:47 - 2015-03-01 10:47 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2015-03-01 10:35 - 2015-03-01 10:35 - 00000000 ____D () C:\Users\Joschi\AppData\Roaming\TuneUp Software
2015-03-01 10:33 - 2015-03-01 10:44 - 00000000 __SHD () C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
2015-03-01 10:33 - 2015-03-01 10:35 - 00000000 ____D () C:\ProgramData\TuneUp Software
2015-03-01 10:31 - 2015-03-01 10:33 - 28181408 _____ (TuneUp Software) C:\Users\Joschi\Downloads\TuneUpUtilities2013_de-DE.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-03-18 23:58 - 2014-02-17 22:02 - 00015092 _____ () C:\Users\Joschi\Downloads\FRST.txt
2015-03-18 23:58 - 2014-02-17 22:02 - 00000000 ____D () C:\FRST
2015-03-18 23:49 - 2013-02-19 09:43 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-18 23:20 - 2012-08-03 00:02 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2015-03-18 23:20 - 2012-08-03 00:02 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2015-03-18 23:20 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-03-18 23:15 - 2013-02-18 10:03 - 00000401 _____ () C:\Users\Joschi\AppData\Roaming\sp_data.sys
2015-03-18 23:14 - 2014-02-17 23:01 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-03-18 23:13 - 2012-08-02 14:24 - 00043978 _____ () C:\Windows\PFRO.log
2015-03-18 23:13 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-03-18 23:12 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2015-03-18 23:11 - 2014-02-18 00:43 - 00000000 ____D () C:\AdwCleaner
2015-03-18 23:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru
2015-03-18 21:59 - 2014-02-17 23:01 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-03-18 21:00 - 2012-10-23 23:25 - 00000000 ____D () C:\ProgramData\Temp
2015-03-18 10:38 - 2013-02-18 10:08 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3714319823-260000009-872883684-1001
2015-03-17 20:42 - 2014-02-17 22:03 - 00039035 _____ () C:\Users\Joschi\Downloads\Addition.txt
2015-03-17 17:02 - 2014-05-13 20:36 - 00000000 ____D () C:\BigFishGamesCache
2015-03-17 17:00 - 2014-05-13 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-03-17 10:04 - 2013-03-23 17:06 - 00000000 ____D () C:\Zylom Games
2015-03-17 10:04 - 2013-03-23 17:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zylom
2015-03-17 10:04 - 2013-03-23 17:06 - 00000000 ____D () C:\Program Files (x86)\RealArcade
2015-03-17 10:03 - 2014-02-11 21:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Purplehills
2015-03-17 10:03 - 2014-02-11 21:19 - 00000000 ____D () C:\Program Files (x86)\Purplehills
2015-03-17 10:00 - 2014-02-01 20:23 - 00000000 ____D () C:\Users\Joschi\AppData\Roaming\cerasus.media
2015-03-17 10:00 - 2014-02-01 20:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\play+smile
2015-03-17 10:00 - 2014-02-01 20:11 - 00000000 ____D () C:\Program Files (x86)\play+smile
2015-03-16 23:30 - 2014-02-17 23:00 - 00000000 ____D () C:\Users\Joschi\Desktop\mbar
2015-03-11 20:52 - 2013-02-19 09:39 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-10 22:03 - 2012-10-23 23:28 - 01869237 _____ () C:\Windows\WindowsUpdate.log
2015-03-06 15:01 - 2015-01-26 20:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2015-03-06 11:03 - 2015-01-21 17:59 - 00000000 ____D () C:\ProgramData\Package Cache
2015-03-06 11:03 - 2013-02-23 14:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-03-06 11:03 - 2013-02-23 14:49 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-03-01 11:04 - 2013-02-25 10:34 - 00000000 ____D () C:\Users\Joschi\AppData\Local\Adobe
==================== Files in the root of some directories =======
2013-02-18 10:03 - 2015-03-18 23:15 - 0000401 _____ () C:\Users\Joschi\AppData\Roaming\sp_data.sys
2014-02-17 11:14 - 2014-02-17 11:14 - 0825216 _____ (AnyProtect.com) C:\Users\Joschi\AppData\Local\nseD7D0.tmp
2012-08-17 01:52 - 2012-07-30 07:03 - 0000217 _____ () C:\ProgramData\SetStretch.cmd
2012-08-17 01:52 - 2009-07-22 11:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
Some content of TEMP:
====================
C:\Users\Joschi\AppData\Local\Temp\avgnt.exe
C:\Users\Joschi\AppData\Local\Temp\bfggun.exe
C:\Users\Joschi\AppData\Local\Temp\EBU1DC1.exe
C:\Users\Joschi\AppData\Local\Temp\EBU22D2.DLL
C:\Users\Joschi\AppData\Local\Temp\install_flashplayer16x32_ltr5x64d_awc_aih(2).exe
C:\Users\Joschi\AppData\Local\Temp\Quarantine.exe
C:\Users\Joschi\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-03-18 10:38
==================== End Of Log ============================ --- --- --- |