Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-03-2017 Ran by [removed] (administrator) on PLC (09-03-2017 20:31:25) Running from C:\Users\[removed]\Downloads [removed] Platform: Windows 10 Pro Version 1511 (X64) Language: Englisch (Vereinigte Staaten) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Hewlett-Packard Company) C:\Program Files (x86)\HP\Common\HPSupportSolutionsFrameworkService.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe () C:\Program Files\WindowsApps\Microsoft.Messaging_1.10.22012.0_x86__8wekyb3d8bbwe\SkypeHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (© 2015 Microsoft Corporation) C:\Users\Jo\AppData\Local\Microsoft\BingSvc\BingSvc.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe (Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Online.io Application\OnlineGuardian-v2.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Traffic Exchange\OnlineGuardian-v2.exe (Microsoft Corporation) C:\Windows\System32\InstallAgent.exe () C:\Program Files\RogueKiller\RogueKiller64.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Traffic Exchange\Online-Guardian-v2.0.9.exe (Microleaves LTD) C:\Program Files (x86)\Microleaves\Online.io Application\Online-Guardian-v2.0.9.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13671792 2014-03-14] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-04-11] (Intel Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [909744 2017-03-03] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [CallControl 4.7] => C:\PROGRAM FILES (X86)\FAXTALK COMMUNICATOR\FTCtrl32.exe [176128 2007-06-26] (Thought Communications, Inc.) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Avira SystrayStartTrigger] => C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [61896 2016-12-29] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-08-24] (Adobe Systems Incorporated) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23818360 2016-11-30] (Google) HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2014-12-12] (Google Inc.) HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [uTorrent] => C:\Users\Jo\AppData\Roaming\uTorrent\uTorrent.exe [2143936 2017-02-15] (BitTorrent Inc.) HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [Lync] => C:\Program Files\Microsoft Office\Office15\lync.exe [27888296 2015-11-18] (Microsoft Corporation) HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27427808 2017-02-08] (Skype Technologies S.A.) HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [BingSvc] => C:\Users\Jo\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-12-14] (© 2015 Microsoft Corporation) HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\...\Run: [GoogleChromeAutoLaunch_CC4943231DFE8AADB1B60B5D96A049CD] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [945496 2017-02-01] (Google Inc.) HKU\S-1-5-18\...\Run: [] => [X] HKLM\...\Providers\zmdpb4co: C:\Program Files (x86)\Mirylazat Debuger\local64spl.dll [307200 2017-03-09] () ShellExecuteHooks: No Name - {A93D5D5C-FFDC-11E6-B921-64006A5CFC23} - C:\Users\Jo\AppData\Roaming\Wherksqiry\Prwitshwigh.dll -> No File ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-11-30] (Google) ShellIconOverlayIdentifiers: [ MagentaOverlayIcon1] -> {70fd746c-367b-3030-8aa3-9170bba946b5} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ MagentaOverlayIcon2] -> {975d4594-41a0-3903-a44e-ce7109705240} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ MagentaOverlayIcon3] -> {4e36001f-6b82-3b12-8348-64d682964de9} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ MagentaOverlayIcon4] -> {47418e6f-8c1d-3223-bef9-2ba1bc655f28} => C:\WINDOWS\system32\mscoree.dll [2015-10-30] (Microsoft Corporation) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-05-22] () ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => -> No File Startup: C:\Users\Jo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagentaCLOUD.lnk [2016-02-14] ShortcutTarget: MagentaCLOUD.lnk -> C:\Users\Jo\AppData\Roaming\Telekom\MagentaCloud\MagentaCloud.App.exe () GroupPolicy: Restriction <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] [removed] [removed] Tcpip\..\Interfaces\{58f06794-ba47-43e9-824c-98a19306f988}: [DhcpNameServer] [removed] [removed] Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://ar.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10270__170130__yaie HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.msn.com/?pc=SK2M&ocid=SK2MDHP&osmkt=en-ww SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-21-3600067520-4028146683-1955487546-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3600067520-4028146683-1955487546-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://ar.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10270__170130__yaie&p={searchTerms} BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-11-18] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_112\bin\ssv.dll [2016-10-20] (Oracle Corporation) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-15] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_112\bin\jp2ssv.dll [2016-10-20] (Oracle Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-11-18] (Microsoft Corporation) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-15] (Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.) Toolbar: HKU\S-1-5-21-3600067520-4028146683-1955487546-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-04-01] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF ProfilePath: C:\Users\Jo\AppData\Roaming\Mozilla\Firefox\naweriweentcofise\Profiles\sOBiWv3p.default\Profiles\sOBiWv3p.default [not found] FF ProfilePath: C:\Users\Jo\AppData\Roaming\Mozilla\Firefox\Profiles\sOBiWv3p.default [2017-03-09] FF NewTab: Mozilla\Firefox\Profiles\sOBiWv3p.default -> hxxps://ar.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10270__170130__yaff FF DefaultSearchEngine: Mozilla\Firefox\Profiles\sOBiWv3p.default -> Yahoo® FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\sOBiWv3p.default -> Bing FF SelectedSearchEngine: Mozilla\Firefox\Profiles\sOBiWv3p.default -> Yahoo® FF Homepage: Mozilla\Firefox\Profiles\sOBiWv3p.default -> hxxps://www.google.com/ FF Keyword.URL: Mozilla\Firefox\Profiles\sOBiWv3p.default -> user_pref("keyword.URL", true); FF Extension: (Avira Browser Safety) - C:\Users\Jo\AppData\Roaming\Mozilla\Firefox\Profiles\sOBiWv3p.default\Extensions\[removed] [2017-02-10] FF Extension: (Bing Search) - C:\Users\Jo\AppData\Roaming\Mozilla\Firefox\Profiles\sOBiWv3p.default\Extensions\[removed] [2015-12-14] FF Extension: (savetexttofile) - C:\Users\Jo\AppData\Roaming\Mozilla\Firefox\Profiles\sOBiWv3p.default\Extensions\[removed] [2016-12-22] FF Extension: (SHA-1 deprecation staged rollout) - C:\Users\Jo\AppData\Roaming\Mozilla\Firefox\Profiles\sOBiWv3p.default\features\{ffcbc99b-7c99-48d1-8dc3-c49debe9a9e0}\[removed] [2017-03-03] FF SearchPlugin: C:\Users\Jo\AppData\Roaming\Mozilla\Firefox\Profiles\sOBiWv3p.default\searchplugins\zmdpb4co.xml [2017-03-09] FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-14] () FF Plugin: @java.com/DTPlugin,version=11.112.2 -> C:\Program Files\Java\jre1.8.0_112\bin\dtplugin\npDeployJava1.dll [2016-10-20] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.112.2 -> C:\Program Files\Java\jre1.8.0_112\bin\plugin2\npjp2.dll [2016-10-20] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-08-24] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-14] () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-18] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-08-24] (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2015-11-18] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-06-30] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-06-25] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-06-25] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-06-25] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-06-25] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-06-25] (Apple Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://www.google.com/","hxxp://www.google.com/" CHR Profile: C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-03-09] <==== ATTENTION CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-17] CHR Extension: (MyMaps) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\alhfkbklfdhcdbkgaggadneanphjhpok [2015-05-23] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-17] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-25] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-28] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-17] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-20] CHR Extension: (Hacker Vision) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\fommidcneendjonelhhhkmoekeicedej [2017-01-03] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Arabic) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-02-25] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-02-25] CHR Extension: (Skype) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-08] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lkppllfomiokdplehmmhdogobccbhleo [2015-05-23] CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-12-15] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2016-09-22] CHR Extension: (hxxps://www.google.com/maps/d/) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\moigknjmimdjfgmcdohhlbigpodggoam [2015-05-23] CHR Extension: (Chrome Web Store Payments) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08] CHR Extension: (My Chrome Theme) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2015-08-27] CHR Extension: (No Name) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28] CHR Extension: (Chrome Media Router) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-07] CHR Profile: C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default [2017-03-09] CHR Extension: (Google Präsentationen) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-09] CHR Extension: (Google Docs) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-09] CHR Extension: (Google Drive) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-09] CHR Extension: (YouTube) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-09] CHR Extension: (Google Tabellen) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-09] CHR Extension: (Avira Browserschutz) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2017-03-09] CHR Extension: (Hacker Vision) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\fommidcneendjonelhhhkmoekeicedej [2017-03-09] CHR Extension: (Google Docs Offline) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-09] CHR Extension: („Merken“-Button von Pinterest) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-03-09] CHR Extension: (Skype) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-03-09] CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2017-03-09] CHR Extension: (Chrome-Erweiterung für Google Notizen) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2017-03-09] CHR Extension: (https://www.google.com/maps/d/) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\moigknjmimdjfgmcdohhlbigpodggoam [2017-03-09] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09] CHR Extension: (Mein Chrome-Design) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2017-03-09] CHR Extension: (Google Mail) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-09] CHR Extension: (Chrome Media Router) - C:\Users\Jo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-09] CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-3600067520-4028146683-1955487546-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-08-24] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-01-19] (Adobe Systems, Incorporated) S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [1115552 2017-03-03] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [487424 2017-03-03] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [487424 2017-03-03] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1519144 2017-03-03] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [372272 2016-12-29] (Avira Operations GmbH & Co. KG) S2 CCALib8; C:\Program Files (x86)\Canon\CAL\CALMAIN.exe [96341 2006-03-30] (Canon Inc.) [File not signed] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe [89840 2015-03-28] (Hewlett-Packard Company) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-04-11] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-16] (Intel Corporation) S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\LENOVO\easyplussdk\bin\EPHotspot64.exe [625632 2015-07-22] (Lenovo) S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation) S2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [161824 2017-03-03] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [163976 2017-03-03] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [44488 2017-03-03] (Avira Operations GmbH & Co. KG) R2 avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [88488 2017-03-03] (Avira Operations GmbH & Co. KG) R0 avusbflt; C:\WINDOWS\System32\Drivers\avusbflt.sys [48584 2017-03-03] (Avira Operations GmbH & Co. KG) R3 ManyCam; C:\WINDOWS\system32\DRIVERS\mcvidrv.sys [49272 2014-12-29] (Visicom Media Inc.) S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-12-14] (Malwarebytes) S3 mcaudrv_simple; C:\WINDOWS\system32\drivers\mcaudrv_x64.sys [35960 2014-12-29] (Visicom Media Inc.) R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation) R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek ) R3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [3860224 2015-08-05] (Realtek Semiconductor Corporation ) R3 SensorsSimulatorDriver; C:\WINDOWS\system32\DRIVERS\WUDFRd.sys [216064 2015-10-30] (Microsoft Corporation) U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-03-09] () S1 UsbCharger; C:\WINDOWS\System32\DRIVERS\UsbCharger.sys [21584 2013-05-06] () S3 VCSVADHWSer; C:\WINDOWS\system32\DRIVERS\vcsvad.sys [21504 2008-12-26] (Avnex) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation) R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-07-10] (Intel Corporation) S2 RtNdPt630; \SystemRoot\system32\DRIVERS\RtNdPt630.sys [X] S3 RTTEAMPT; \SystemRoot\system32\DRIVERS\RtTeam620.sys [X] S3 RTVLANPT; \SystemRoot\system32\DRIVERS\RtVlan620.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-03-09 20:31 - 2017-03-09 20:31 - 00033339 _____ C:\Users\Jo\Downloads\FRST.txt 2017-03-09 20:24 - 2017-03-09 20:31 - 00000000 ____D C:\FRST 2017-03-09 20:23 - 2017-03-09 20:24 - 02423808 _____ (Farbar) C:\Users\Jo\Downloads\FRST64.exe 2017-03-09 18:12 - 2017-03-09 20:03 - 00000000 ___HD C:\Users\Public\Documents\AdobeGC 2017-03-09 02:46 - 2017-03-09 02:46 - 00000000 ____D C:\ProgramData\Microleaves 2017-03-09 02:43 - 2017-03-09 20:31 - 00000338 _____ C:\WINDOWS\Tasks\Online Application v209.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000338 _____ C:\WINDOWS\Tasks\Online Application v209 Guardian.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000338 _____ C:\WINDOWS\Tasks\Online Application v209 Guard.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000328 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 3.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000328 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 2.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000328 _____ C:\WINDOWS\Tasks\Traffic Exchange v209 - 1.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000328 _____ C:\WINDOWS\Tasks\Online Application v2.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000328 _____ C:\WINDOWS\Tasks\Online Application v2 Guardian.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000328 _____ C:\WINDOWS\Tasks\Online Application v2 Guard.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000318 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 3.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000318 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 2.job 2017-03-09 02:43 - 2017-03-09 20:31 - 00000318 _____ C:\WINDOWS\Tasks\Traffic Exchange v2 - 1.job 2017-03-09 02:43 - 2017-03-09 17:46 - 00000370 ____H C:\WINDOWS\Tasks\Traffic Exchange Updater.job 2017-03-09 02:43 - 2017-03-09 06:46 - 00000384 _____ C:\WINDOWS\Tasks\Online Application Updater.job 2017-03-09 02:43 - 2017-03-09 02:43 - 00006146 _____ C:\WINDOWS\System32\Tasks\Mirylazat Debuger 2017-03-09 02:43 - 2017-03-09 02:43 - 00005136 _____ C:\WINDOWS\System32\Tasks\Phonusserrsp 2017-03-09 02:43 - 2017-03-09 02:43 - 00003722 _____ C:\WINDOWS\System32\Tasks\Online Application Guardian 2017-03-09 02:43 - 2017-03-09 02:43 - 00003716 _____ C:\WINDOWS\System32\Tasks\Online Application Guard 2017-03-09 02:43 - 2017-03-09 02:43 - 00003708 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Guardian 2017-03-09 02:43 - 2017-03-09 02:43 - 00003704 _____ C:\WINDOWS\System32\Tasks\Online Application 2017-03-09 02:43 - 2017-03-09 02:43 - 00003702 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Guard 2017-03-09 02:43 - 2017-03-09 02:43 - 00003690 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange 2017-03-09 02:43 - 2017-03-09 02:43 - 00003278 _____ C:\WINDOWS\System32\Tasks\Online Application Updater 2017-03-09 02:43 - 2017-03-09 02:43 - 00003258 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange Updater 2017-03-09 02:43 - 2017-03-09 02:43 - 00003244 _____ C:\WINDOWS\System32\Tasks\Online Application v209 Guardian 2017-03-09 02:43 - 2017-03-09 02:43 - 00003238 _____ C:\WINDOWS\System32\Tasks\Online Application v209 Guard 2017-03-09 02:43 - 2017-03-09 02:43 - 00003230 _____ C:\WINDOWS\System32\Tasks\Online Application v2 Guardian 2017-03-09 02:43 - 2017-03-09 02:43 - 00003226 _____ C:\WINDOWS\System32\Tasks\Online Application v209 2017-03-09 02:43 - 2017-03-09 02:43 - 00003224 _____ C:\WINDOWS\System32\Tasks\Online Application v2 Guard 2017-03-09 02:43 - 2017-03-09 02:43 - 00003220 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 3 2017-03-09 02:43 - 2017-03-09 02:43 - 00003220 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 2 2017-03-09 02:43 - 2017-03-09 02:43 - 00003220 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v209 - 1 2017-03-09 02:43 - 2017-03-09 02:43 - 00003212 _____ C:\WINDOWS\System32\Tasks\Online Application v2 2017-03-09 02:43 - 2017-03-09 02:43 - 00003206 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 3 2017-03-09 02:43 - 2017-03-09 02:43 - 00003206 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 2 2017-03-09 02:43 - 2017-03-09 02:43 - 00003206 _____ C:\WINDOWS\System32\Tasks\Traffic Exchange v2 - 1 2017-03-09 02:43 - 2017-03-09 02:43 - 00000000 ____D C:\Users\Jo\AppData\Roaming\Microleaves 2017-03-09 02:43 - 2017-03-09 02:43 - 00000000 ____D C:\Users\Jo\AppData\Local\Borergh 2017-03-09 02:43 - 2017-03-09 02:43 - 00000000 ____D C:\Users\Default\AppData\Local\AdvinstAnalytics 2017-03-09 02:43 - 2017-03-09 02:43 - 00000000 ____D C:\Users\Default User\AppData\Local\AdvinstAnalytics 2017-03-09 02:43 - 2017-03-09 02:43 - 00000000 ____D C:\Program Files (x86)\Mirylazat Debuger 2017-03-09 02:43 - 2017-03-09 02:43 - 00000000 ____D C:\Program Files (x86)\Microleaves 2017-03-09 02:41 - 2017-03-09 02:42 - 07982620 _____ C:\Users\Jo\Desktop\Meo.File.Encryption.Software.2.keygen.by.DBC.exe 2017-02-23 04:37 - 2017-02-23 04:37 - 00000000 ____D C:\Program Files (x86)\Deutsches-Fernsehen.net 2017-02-19 05:26 - 2017-02-19 05:26 - 06560187 _____ C:\Users\Jo\Documents\wickham-the-inheritance-of-rome.pdf 2017-02-14 03:26 - 2017-02-14 03:26 - 00145008 _____ C:\Users\Jo\Desktop\none-D_NQ_NP_496905-MLA25125797848_102016-F.jpg.webp 2017-02-10 17:28 - 2017-02-10 17:28 - 00000000 ____D C:\searchplugins 2017-02-10 14:10 - 2017-02-10 14:10 - 00002221 _____ C:\Users\Public\Desktop\Google Earth.lnk 2017-02-10 14:10 - 2017-02-10 14:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth 2017-02-10 04:26 - 2017-02-10 05:38 - 00000837 _____ C:\Users\Jo\Desktop\grupo facebook.txt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-03-09 20:30 - 2014-12-27 01:25 - 00000000 ____D C:\Users\Jo\AppData\Roaming\uTorrent 2017-03-09 20:15 - 2015-05-27 17:33 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2017-03-09 20:12 - 2015-10-30 04:11 - 00000000 ____D C:\WINDOWS\CbsTemp 2017-03-09 20:03 - 2015-11-24 04:20 - 02046638 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2017-03-09 20:03 - 2015-10-30 04:21 - 00000000 ____D C:\WINDOWS\INF 2017-03-09 20:03 - 2014-12-12 16:38 - 00916600 _____ C:\WINDOWS\system32\perfh007.dat 2017-03-09 20:03 - 2014-12-12 16:38 - 00195898 _____ C:\WINDOWS\system32\perfc007.dat 2017-03-09 19:59 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\NDF 2017-03-09 19:58 - 2016-10-19 20:19 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys 2017-03-09 19:57 - 2016-11-18 03:38 - 00000000 ____D C:\Users\Jo\AppData\LocalLow\Mozilla 2017-03-09 19:57 - 2015-11-24 04:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2017-03-09 19:57 - 2015-11-24 04:14 - 00000000 ____D C:\Users\Jo 2017-03-09 18:15 - 2016-10-20 04:46 - 00000000 ____D C:\Users\Jo\AppData\Local\CrashDumps 2017-03-09 15:13 - 2014-12-12 16:11 - 00004138 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{680C379D-C058-4CC6-9BFA-BA24CCC240B1} 2017-03-09 03:17 - 2017-01-30 20:07 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2017-03-09 03:17 - 2015-10-30 03:28 - 03670016 ___SH C:\WINDOWS\system32\config\BBI 2017-03-09 03:17 - 2015-05-27 17:11 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-03-09 03:17 - 2015-04-17 03:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-03-09 03:15 - 2017-01-30 20:07 - 00000000 ____D C:\Users\Jo\AppData\Roaming\Lavasoft 2017-03-09 02:32 - 2015-06-20 20:53 - 00000000 ____D C:\Users\Jo\Documents\DxO OpticsPro 10 logs 2017-03-09 02:31 - 2016-12-07 04:14 - 00000000 ____D C:\Users\Jo\AppData\Roaming\CDisplayEx 2017-03-09 02:29 - 2016-07-22 03:25 - 00000000 ____D C:\Users\Jo\Desktop\Adobe 2017-03-09 02:29 - 2016-02-14 03:43 - 00000000 ____D C:\Users\Jo\Desktop\recetas 2017-03-09 02:00 - 2015-02-21 03:12 - 00000000 ____D C:\Users\Jo\AppData\Local\Adobe 2017-03-07 15:15 - 2014-12-29 22:34 - 00000000 ____D C:\Users\Jo\AppData\Roaming\vlc 2017-03-06 07:29 - 2014-12-19 13:09 - 00000000 ____D C:\Users\Jo\AppData\Roaming\Skype 2017-03-06 01:09 - 2016-10-20 20:21 - 00000000 ____D C:\Users\Jo\AppData\Local\ManyCam 2017-03-05 01:02 - 2015-12-15 23:03 - 00001456 _____ C:\Users\Jo\AppData\Local\Adobe Save for Web 13.0 Prefs 2017-03-03 00:41 - 2014-12-12 17:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira 2017-03-03 00:40 - 2016-10-06 04:51 - 00048584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avusbflt.sys 2017-03-03 00:40 - 2014-12-12 17:54 - 00163976 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2017-03-03 00:40 - 2014-12-12 17:54 - 00161824 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2017-03-03 00:40 - 2014-12-12 17:54 - 00088488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys 2017-03-03 00:40 - 2014-12-12 17:54 - 00044488 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys 2017-03-02 21:45 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\AppReadiness 2017-03-02 05:05 - 2016-06-17 19:54 - 00000000 ____D C:\Users\Jo\Desktop\transferir 2017-03-02 03:10 - 2016-10-18 23:46 - 00000000 ____D C:\Users\Jo\AppData\Roaming\NCH Software 2017-03-01 21:49 - 2015-11-01 02:22 - 00003956 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1446355360 2017-03-01 21:49 - 2015-11-01 02:22 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk 2017-03-01 21:49 - 2015-11-01 02:22 - 00000000 ____D C:\Program Files (x86)\Opera 2017-02-28 23:00 - 2015-02-16 20:59 - 00000000 ____D C:\Users\Jo\AppData\Local\ElevatedDiagnostics 2017-02-24 04:52 - 2015-04-13 21:00 - 00000000 ____D C:\Users\Jo\Documents\GomPlayer 2017-02-23 04:37 - 2016-11-20 08:46 - 00001106 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deutsches-Fernsehen.net.lnk 2017-02-23 04:37 - 2016-11-20 08:46 - 00001094 _____ C:\Users\Public\Desktop\Deutsches-Fernsehen.net.lnk 2017-02-20 23:17 - 2014-12-19 13:09 - 00000000 ___RD C:\Program Files (x86)\Skype 2017-02-20 23:17 - 2014-12-19 13:09 - 00000000 ____D C:\ProgramData\Skype 2017-02-15 14:35 - 2016-04-01 18:54 - 00000000 ____D C:\Users\Jo\Desktop\paginas 2017-02-15 03:00 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports 2017-02-14 16:15 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed 2017-02-14 16:15 - 2015-10-30 04:24 - 00000000 ____D C:\WINDOWS\system32\Macromed 2017-02-14 03:27 - 2016-12-19 03:44 - 00001256 _____ C:\Users\Jo\Desktop\Knight's Gambit.lnk 2017-02-14 03:27 - 2016-11-06 08:51 - 00001211 _____ C:\Users\Jo\Desktop\VideoPad Video Editor.lnk 2017-02-14 03:27 - 2016-07-22 03:34 - 00001061 _____ C:\Users\Jo\Desktop\Adobe Lightroom.lnk 2017-02-14 03:27 - 2016-02-20 00:30 - 00001096 _____ C:\Users\Jo\Desktop\MEO Encryption Software.lnk 2017-02-14 03:27 - 2015-12-15 22:56 - 00001099 _____ C:\Users\Jo\Desktop\Exif Pilot.lnk 2017-02-14 03:27 - 2015-11-01 02:23 - 00002348 _____ C:\Users\Jo\Desktop\Chromium.lnk 2017-02-14 03:27 - 2015-04-06 22:47 - 00000888 _____ C:\Users\Jo\Desktop\Downloads.lnk 2017-02-14 03:27 - 2014-12-22 14:58 - 00002323 _____ C:\Users\Jo\Desktop\Chrome App Launcher.lnk 2017-02-10 14:10 - 2014-12-12 16:58 - 00000000 ____D C:\Program Files (x86)\Google ==================== Files in the root of some directories ======= 2015-07-15 06:01 - 2015-07-15 06:01 - 0000132 _____ () C:\Users\Jo\AppData\Roaming\Adobe GIF Format CS6 Prefs 2015-11-14 03:07 - 2015-11-14 03:07 - 0000132 _____ () C:\Users\Jo\AppData\Roaming\Adobe IllExport Filter CS6 Prefs 2015-03-08 06:39 - 2015-03-08 06:40 - 0000132 _____ () C:\Users\Jo\AppData\Roaming\Adobe IllExport-Filter CC - Voreinstellungen 2015-06-25 04:15 - 2015-07-24 17:48 - 0027996 _____ () C:\Users\Jo\AppData\Roaming\net.telestream.producer.xml 2015-06-25 03:38 - 2015-06-25 04:15 - 0000732 _____ () C:\Users\Jo\AppData\Roaming\net.telestream.ustreamproducer.prefs.xml 2015-11-01 03:22 - 2016-07-08 00:29 - 0000210 _____ () C:\Users\Jo\AppData\Roaming\WB.CFG 2015-12-15 23:03 - 2017-03-05 01:02 - 0001456 _____ () C:\Users\Jo\AppData\Local\Adobe Save for Web 13.0 Prefs 2014-12-20 06:03 - 2015-12-15 01:22 - 0013824 _____ () C:\Users\Jo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2016-05-12 20:53 - 2016-05-12 20:53 - 0000000 _____ () C:\Users\Jo\AppData\Local\{C1FEA6C7-02E2-4C37-A9C4-9CF7639FF0D7} 2015-04-09 03:24 - 2015-04-09 03:24 - 0000057 _____ () C:\ProgramData\Ament.ini 2015-11-24 04:14 - 2015-11-24 04:14 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some files in TEMP: ==================== 2017-03-09 19:58 - 2015-10-30 04:18 - 1817160 _____ (Microsoft Corporation) C:\Users\Jo\AppData\Local\Temp\dllnt_dump.dll 2016-02-23 20:28 - 2016-02-23 20:28 - 0000000 ____D () C:\Users\pauli_000\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-03-09 16:44 ==================== End of FRST.txt ============================