Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Browser Hijacking, no wierd add-ons installed.


  • This topic is locked This topic is locked
10 replies to this topic

#1 ElDochart

ElDochart

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 28 March 2015 - 08:04 AM

My browser is being redirected to various websites when I try to go to a new page, or click a link.  The first redirect is to b00kmarks.com, Creativedesignblogs.com, or feed4.hype-ads.com, which are all blank pages and immediately redirect to seemingly random websites, like redirecting to a search for "give" on amazon.com.  It does not happen every time, but often enough to be annyoing.

The only add-on I have installed is the Reddit Enhancement Suite. 

 

I'm running Windows 8.1, and only use Firefox, although I've tested the other browsers, and it is redirecting on Chrome and IE as well. 



BC AdBot (Login to Remove)

 


#2 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:16 PM

Posted 28 March 2015 - 08:11 AM

Hi & :welcome: to Bleeping Computer Forums!
My name is Jürgen and I will be assisting you with your Malware related problems. :warrior:

Before we move on, please read the following points carefully: :exclame:
  • My native language isn't English. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.
  • Please read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while you are follow my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or Add/ Remove Software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all Logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 5 days from this initial or any subsequent post, then this thread will be closed.
  • If I don't reply within 24 hours please PM me!
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
Step 1

Please run a FRST scan. This will help us diagnose your problem.

frst.pngfrstscan.png
Please download Farbar Recovery Scan Tool and save it to your Desktop.
(If you are not sure which version (32-/64-bit) applies to your system, download and try to start both of them as just the right one will run.)
  • Start FRST with administator privileges.
  • Make sure the option Addition.txt is checked and press the Scan button.
  • When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.
  • Please copy and paste these logs in your next reply.

regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#3 ElDochart

ElDochart
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 28 March 2015 - 08:46 AM

Addition.txt attached, frst is too big of a file.

Attached Files



#4 ElDochart

ElDochart
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 28 March 2015 - 08:47 AM

Compressed it here if that works for you.

Attached Files

  • Attached File  FRST.zip   66.52KB   3 downloads


#5 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:16 PM

Posted 28 March 2015 - 08:53 AM

:thumbup2:

 

OK, will analyse the logs and post back with first instructions.


regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#6 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:16 PM

Posted 28 March 2015 - 12:11 PM

Hi,
 
warning.gif P2P warning

Going over your logs I noticed that you have µTorrent installed.

  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a wide variety of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.

It is pretty much certain that if you continue to use P2P programs, you will get infected again.
I would recommend that you uninstall µTorrent, however that choice is up to you.

If you wish to keep it, please do not use it until your computer is cleaned.

Step 1

Please download adwcleaner.png AdwCleaner (by Xplode) and save it to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select "Run As Administrator"
  • Click on the Scan button.
  • After the scan has finished, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • After rebooting, a log file (that is saved in C:\AdwCleaner[S#].txt) will open automatically.
    Copy and paste the contents of that logfile in your next reply.

Step 2

v21logo.PNG

Please download and install Malwarebytes Anti-Malware.

  • Please open Malwarebytes Anti-Malware and update the database.
  • Click "Settings" [1] and go to "Detection and Protection" [2]
  • Make sure "Scan for Rootkits" is checked.
  • Click on Dashboard [3], then click on Scan Now [4] to start the scan.
    :exclame: If Malware or Potentially Unwanted Programs [PUPs] are found, you will receive a prompt:
    m21p.png
  • Click on "Remove Selected" [5].
  • Then click "Save Results" [6] and select
    m21p4.png
  • Return to our forum. Paste your log into your next reply and then click Finish [7].

mbamv21.gif

Step 3

frst.pngfrstscan.png

Start FRST with administator privileges.

  • Make sure the following option is checked: addition.png
  • Press the Scan button.
  • When finished, FRST will produce two logs (FRST.txt and Addition.txt) in the same directory the tool was run from.
    Please copy and paste these logs in your next reply.

Edited by deeprybka, 28 March 2015 - 12:12 PM.

regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#7 ElDochart

ElDochart
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 28 March 2015 - 02:07 PM

Ok, there's those.

Attached Files



#8 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:16 PM

Posted 29 March 2015 - 04:45 AM

Hi,

Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

Step 1

zoek.jpg

Please download 51a612a8b27e2-Zoek.pngZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)

  • Right-click on 51a612a8b27e2-Zoek.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
    systemspecs;
    ipconfig /flushdns >> %temp%\log.txt;b
    filesrcm;
    FFdefaults;
    iedefaults;
    emptyclsid;
    autoclean;
    
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.


regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#9 ElDochart

ElDochart
  • Topic Starter

  • Members
  • 5 posts
  • OFFLINE
  •  
  • Local time:03:16 PM

Posted 30 March 2015 - 09:01 AM

Zoek.exe v5.0.0.0 Updated 29-March-2015
Tool run by David on Mon 03/30/2015 at  9:47:47.52.
Microsoft Windows 8.1 6.3.9600  x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\David\Downloads\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

3/30/2015 9:48:27 AM Zoek.exe System Restore Point Created Successfully.

==== Empty Folders Check ======================

C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\Users\David\AppData\Roaming\uTorrent deleted successfully
C:\Users\David\AppData\Local\Adobe deleted successfully
C:\Users\David\AppData\Local\PackageStaging deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\ixfac9rl.default\prefs.js:
user_pref("browser.startup.homepage", "http://reddit.com/");
user_pref("browser.search.defaultenginename.US", "Google");

Added to C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\ixfac9rl.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Batch Command(s) Run By Tool======================


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

==== Deleting Files \ Folders ======================

C:\PROGRA~2\AGEIA Technologies not found
C:\Users\David\AppData\Roaming\.minecraft deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Windows\SysNative\config\systemprofile\Searches deleted
C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\ixfac9rl.default\jetpack deleted

==== System Specs ======================

Windows: Windows Version 6.2 (Build 9200)
Memory (RAM): 8110 MB
CPU Info: Intel® Core™ i5-4210U CPU @ 1.70GHz
CPU Speed: 2412.9 MHz
Sound Card: Speakers / Headphones (Realtek  |
Display Adapters: Intel® HD Graphics Family | Intel® HD Graphics Family | Intel® HD Graphics Family
Monitors: 1x; Generic PnP Monitor |
Screen Resolution: 1280 X 720 - 32 bit
Network: Network Present
Network Adapters: Killer e2200 Gigabit Ethernet Controller (NDIS 6.30) | Microsoft Wi-Fi Direct Virtual Adapter | Killer Wireless-n/a/ac 1525 Wireless Network Adapter | Bluetooth Device (Personal Area Network)
CD / DVD Drives: 1x (D: | ) D: ELBY    CLONEDRIVE
Ports: COM Ports NOT Present. LPT Port NOT Present.
Mouse: 2 Button Mouse Present
Hard Disks: C:  228.8GB | X:  750.0MB | Y:  8.3GB
Hard Disks - Free: C:  54.5GB | X:  469.7MB | Y:  746.7MB
Manufacturer *: Alienware
BIOS Info: AT/AT COMPATIBLE |  | ALWARE - 1072009
Time Zone: Eastern Standard Time
Motherboard *: Alienware 0VMGD7
Country: United States
Language: ENU

==== System Specs (Software) ======================

Anti-Virus: Windows Defender On-access scanning disabled (Outdated)
Anti-Spyware: Windows Defender disabled (Outdated)
Default Browser: Firefox    36.0.4
Internet Explorer Version: 11.0.9600.17690
Mozilla Firefox version: 36.0.4 (x86 en-US)
Sun Java version: 1.8.0_31 (32-bit)
Sun Java version: 1.8.0_31 (64-bit)
Flash Player version: 17.0.0.134

==== Files Recently Created / Modified ======================

====== C:\Windows ====
2015-03-10 19:13:15    C10A66189DC8C090E7C84873EDCEBC88    2501368    ----a-w-    C:\Windows\explorer.exe
2015-03-04 19:37:51    80E856B1AFAEB6195EADAAD65945147C    1001472    ----a-w-    C:\Windows\HelpPane.exe
2015-03-04 19:35:50    959A31D0CD013CEA0C66DB7C03BCBDDF    221184    ----a-w-    C:\Windows\notepad.exe
2015-03-04 19:34:41    B67DB709F5FDAA89CA6C2CB6C1E39B3B    154624    ----a-w-    C:\Windows\regedit.exe
2015-03-04 19:34:29    4D9DA155B7B449964E14FC32124CC601    128512    ----a-w-    C:\Windows\splwow64.exe
2015-03-04 19:34:23    727B4519FE9919447108CBEC4768F34A    54272    ----a-w-    C:\Windows\twain_32.dll
2015-03-04 19:32:12    B934411DFE7DEACFA95A1255A48133C9    17408    ----a-w-    C:\Windows\hh.exe
2015-03-04 19:32:10    335C38783B3F1B383ECAC17DB3705895    9728    ----a-w-    C:\Windows\winhlp32.exe
2015-03-04 19:32:07    73E19BE0E0ECD88616B5762F621B0226    11264    ----a-w-    C:\Windows\write.exe
2015-03-01 17:42:08    0D4BB58428F9A81F374CBE9FC5CE647D    883958077    ----a-w-    C:\Windows\MEMORY.DMP
====== C:\Users\David\AppData\Local\Temp ====
2015-03-28 12:50:23    D41D8CD98F00B204E9800998ECF8427E    0    ----a-w-    C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp\mpam-a23a31e5.exe
====== Java Cache =====
2015-03-01 16:40:54    6E1B6531E1CA1CDAC074A47DB9F598CD    7069    ----a-w-    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13\5b84bc8d-11e42e23
2015-03-01 16:41:00    4F0A617B1C37249759AA46698016543E    85375    ----a-w-    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\25b6ce19-27b1f710
2015-03-01 16:40:52    BDCCB36DDE27BE0BEA4C0422B6D89BE6    418    ----a-w-    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\573ff65b-7cc2e331f00322f69adde8c55e518ae6cc6397ba51ec531c85505abf18a17e69-6.0.lap
2015-03-01 16:40:59    104C510626460C45F4614F116B7DD137    92    ----a-w-    C:\Users\David\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39\a97bb27-12d7f14f7c6b630b805ea8264f2852144bb98733a669c92671095be69f0d67e1-6.0.lap
====== C:\Windows\SysWOW64 =====
2015-03-28 00:16:57    704DFF699CF979DF6854ED442F87C25B    616592    ----a-w-    C:\Windows\SysWOW64\nvStreaming.exe
====== C:\Windows\SysWOW64\drivers =====
====== C:\Windows\Sysnative =====
2015-03-25 19:44:03    DD301FDB003F9B48EB7628A48BF32D23    677888    ----a-w-    C:\Windows\Sysnative\generaltel.dll
2015-03-25 19:44:03    BB86098B80BC4911B52F4C6095E82381    760320    ----a-w-    C:\Windows\Sysnative\invagent.dll
2015-03-25 19:44:03    B770418F0FE64D3E986505A6285E91E9    943104    ----a-w-    C:\Windows\Sysnative\appraiser.dll
2015-03-25 19:44:03    A871B38A544058768F082598412278DB    30720    ----a-w-    C:\Windows\Sysnative\acmigration.dll
2015-03-25 19:44:03    7F19365C2D9CD0AA5E517A96A22AE7C8    1107456    ----a-w-    C:\Windows\Sysnative\aeinv.dll
2015-03-25 19:44:03    4BAF6A3B8DFDDCE080275B236F4B64BC    414208    ----a-w-    C:\Windows\Sysnative\devinv.dll
2015-03-25 19:44:02    4E791CFE387374E8651493557B7F9993    227328    ----a-w-    C:\Windows\Sysnative\aepdu.dll
====== C:\Windows\Sysnative\drivers =====
2015-03-28 18:32:49    E9CD058C79EA15B4AA93E259FA713B07    136408    ----a-w-    C:\Windows\Sysnative\drivers\MBAMSwissArmy.sys
2015-03-28 18:31:04    CF12E148C6FC151335B7D7FE03F1C7A2    25816    ----a-w-    C:\Windows\Sysnative\drivers\mbam.sys
2015-03-28 18:31:04    7FD0FDFB97D80B21195273C4C3810FE1    64216    ----a-w-    C:\Windows\Sysnative\drivers\mwac.sys
2015-03-28 18:31:04    68C3B11D1ED8C97648BEEFEC37E93E74    107736    ----a-w-    C:\Windows\Sysnative\drivers\mbamchameleon.sys
2015-03-24 16:46:55    D41D8CD98F00B204E9800998ECF8427E    0    ---ha-w-    C:\Windows\Sysnative\drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-03-21 22:36:10    D41D8CD98F00B204E9800998ECF8427E    0    ---ha-w-    C:\Windows\Sysnative\drivers\Msft_User_LocationProvider_01_11_00.Wdf
2015-03-21 21:24:21    D41D8CD98F00B204E9800998ECF8427E    0    ---ha-w-    C:\Windows\Sysnative\drivers\Msft_Kernel_netaapl64_01009.Wdf
2015-03-21 21:20:47    8E98D21EE06192492A5671A6144D092F    33240    ----a-w-    C:\Windows\Sysnative\drivers\GEARAspiWDM.sys
2015-03-17 10:54:01    D41D8CD98F00B204E9800998ECF8427E    0    ---ha-w-    C:\Windows\Sysnative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-03-10 19:14:08    D296D0F0DB2CD1504F90405603664493    264000    ----a-w-    C:\Windows\Sysnative\drivers\WdFilter.sys
2015-03-10 19:14:08    9F4DF0043965808973023A9B51A11136    114496    ----a-w-    C:\Windows\Sysnative\drivers\WdNisDrv.sys
2015-03-10 19:14:08    1751F6B031ADAC34724511057D2E455D    44024    ----a-w-    C:\Windows\Sysnative\drivers\WdBoot.sys
2015-03-10 19:13:32    DC66AE45816614D2999DCD3834DCCC4E    167424    -c--a-w-    C:\Windows\Sysnative\drivers\rfcomm.sys
2015-03-10 19:13:32    6D3A2565E01B3E4B0F1BEDB0D4B00B3F    1113920    ----a-w-    C:\Windows\Sysnative\drivers\ndis.sys
2015-03-10 19:13:32    42F88B57CAE42FC10059C887B3FCFCEA    97792    -c--a-w-    C:\Windows\Sysnative\drivers\hidbth.sys
2015-03-04 19:39:28    65454187E0F8B6C0DCECB0287D06EC43    14144    -c--a-w-    C:\Windows\Sysnative\drivers\swenum.sys
2015-03-04 19:39:02    468273F7089A3A33D149955F0F203FA4    2485056    ----a-w-    C:\Windows\Sysnative\drivers\tcpip.sys
2015-03-04 19:39:02    13EFD41E351F31E087283CF66C29A25E    373568    ----a-w-    C:\Windows\Sysnative\drivers\storport.sys
2015-03-04 19:39:02    00C594D5A1DBD22AD8B2902B9F6EFF94    14528    -c--a-w-    C:\Windows\Sysnative\drivers\drmkaud.sys
2015-03-04 19:38:52    7F68063A5A0461E02BC860CE0E6BFDDC    2025792    ----a-w-    C:\Windows\Sysnative\drivers\ntfs.sys
2015-03-04 19:38:07    E1BB0B6F00F470B451AB45EA13EBA0B3    1552704    ----a-w-    C:\Windows\Sysnative\drivers\dxgkrnl.sys
2015-03-04 19:37:51    E796AE43DDD1844281DB4D57294D17C0    533824    -c--a-w-    C:\Windows\Sysnative\drivers\acpi.sys
2015-03-04 19:37:50    982B9495F70FEEA269C48F18E960EFDE    389952    ----a-w-    C:\Windows\Sysnative\drivers\dxgmms1.sys
2015-03-04 19:37:43    00D8AC8E3053290BDE6EA2FB6810D2FC    678400    ----a-w-    C:\Windows\Sysnative\drivers\srv2.sys
2015-03-04 19:37:32    31233271EDE50D1BBB220F78AFA60486    405504    ----a-w-    C:\Windows\Sysnative\drivers\mrxsmb.sys
2015-03-04 19:37:19    C06E8481E068F170A258441639AC5792    551232    -c--a-w-    C:\Windows\Sysnative\drivers\vhdmp.sys
2015-03-04 19:37:06    D24B1945ED1F9C96DA786DBBF1E983CE    415040    -c--a-w-    C:\Windows\Sysnative\drivers\spaceport.sys
2015-03-04 19:36:53    2787A73C848128C950385CB3A63A6B91    337728    ----a-w-    C:\Windows\Sysnative\drivers\Classpnp.sys
2015-03-04 19:36:42    6276AC2AA203CF47811F6EFBBD214FBF    202752    ----a-w-    C:\Windows\Sysnative\drivers\mrxsmb20.sys
2015-03-04 19:36:40    C1FB505A73FA2E9019D32444AB33B75A    354112    ----a-w-    C:\Windows\Sysnative\drivers\fltMgr.sys
2015-03-04 19:36:39    FAA564A13576F9284546BF016D27B551    467776    -c--a-w-    C:\Windows\Sysnative\drivers\USBHUB3.SYS
2015-03-04 19:36:12    C37F4930795B771400C63C3C87E7A6C2    1198080    -c--a-w-    C:\Windows\Sysnative\drivers\bthport.sys
2015-03-04 19:35:49    D7B4859227B02BCC1055B279A63C937F    226304    ----a-w-    C:\Windows\Sysnative\drivers\WUDFRd.sys
2015-03-04 19:35:42    C76097CA941FA7CAFEDB1E557969025C    272384    -c--a-w-    C:\Windows\Sysnative\drivers\portcls.sys
2015-03-04 19:35:22    4E829B18D5BAEC29893792A3C671A847    100672    ----a-w-    C:\Windows\Sysnative\drivers\ksecdd.sys
2015-03-04 19:35:15    BAFF6122CFC9F95CA175AD8C348179A4    88896    ----a-w-    C:\Windows\Sysnative\drivers\partmgr.sys
2015-03-04 19:35:09    481286719402E4BAEFEA0604AB1B5113    113664    ----a-w-    C:\Windows\Sysnative\drivers\WUDFPf.sys
2015-03-04 19:35:08    BAB713B409258DB7B5D9F9693F802B0E    136512    ----a-w-    C:\Windows\Sysnative\drivers\wfplwfs.sys
2015-03-04 19:35:03    E8FFD8BE3C50E7A71C5FBB87BDD1128E    96768    ----a-w-    C:\Windows\Sysnative\drivers\agilevpn.sys
2015-03-04 19:34:54    41F631007A158FEBB67F0E2AD1601BBA    93696    ----a-w-    C:\Windows\Sysnative\drivers\rassstp.sys
2015-03-04 19:34:50    FC0141B4A5AD6D637D883C1A89FC45C5    151040    ----a-w-    C:\Windows\Sysnative\drivers\pacer.sys
2015-03-04 19:34:48    D1D82F007A079A4D623DBD1F36EF30A1    102208    ----a-w-    C:\Windows\Sysnative\drivers\mountmgr.sys
2015-03-04 19:34:48    008F7CED69FD5B30CBDE1E03C6F36A27    445440    ----a-w-    C:\Windows\Sysnative\drivers\nwifi.sys
2015-03-04 19:34:45    F00B189ECA74DDF408AD934ADDC72477    89088    -c--a-w-    C:\Windows\Sysnative\drivers\drmk.sys
2015-03-04 19:34:41    A7C31B168F371E8E6796219F23E354DB    61248    ----a-w-    C:\Windows\Sysnative\drivers\fsdepends.sys
2015-03-04 19:34:40    A1D4D34A56DF1D5122CDB265038A2E72    59712    -c--a-w-    C:\Windows\Sysnative\drivers\kbdclass.sys
2015-03-04 19:34:32    BF8205666BA2F9C2ABFA821DB8230C12    428864    ----a-w-    C:\Windows\Sysnative\drivers\FWPKCLNT.SYS
2015-03-04 19:34:30    A53E798C06D729CCF8459968B4372F6E    89368    ----a-w-    C:\Windows\Sysnative\drivers\vmbkmcl.sys
2015-03-04 19:34:21    6505C9E72910F91D4C317EECF22D1DE6    80896    ----a-w-    C:\Windows\Sysnative\drivers\wanarp.sys
2015-03-04 19:34:16    615DFD97DEA56CE1C3A52185A3038FF8    921920    ----a-w-    C:\Windows\Sysnative\drivers\refs.sys
2015-03-04 19:33:55    511AD3FF957A0127E6BD336FF6F89C38    97048    ----a-w-    C:\Windows\Sysnative\drivers\vmbus.sys
2015-03-04 19:33:53    10A78656BF6126245631705E45F9B9CF    61208    ----a-w-    C:\Windows\Sysnative\drivers\winhv.sys
2015-03-04 19:33:52    EF31713EE4C7CCFE4049F7E7F15645A2    69952    ----a-w-    C:\Windows\Sysnative\drivers\vpci.sys
2015-03-04 19:33:52    8B9486B64E5FC17FB9CC04CA10B77A34    49944    ----a-w-    C:\Windows\Sysnative\drivers\vmstorfl.sys
2015-03-04 19:33:50    269882812E9A68FFF1AFE1283D428322    126464    ----a-w-    C:\Windows\Sysnative\drivers\NdisImPlatform.sys
2015-03-04 19:33:42    6FC047578785B0435F4E2660946D1ADC    74240    ----a-w-    C:\Windows\Sysnative\drivers\mpsdrv.sys
2015-03-04 19:33:33    A2468CC3509394A33C4C32F99563D845    54784    ----a-w-    C:\Windows\Sysnative\drivers\wpcfltr.sys
2015-03-04 19:33:33    1A20F03700D2B2ED775E38D751EF2F63    324928    -c--a-w-    C:\Windows\Sysnative\drivers\USBXHCI.SYS
2015-03-04 19:33:31    F3C060444777A59FC63D920719E43CCD    115712    ----a-w-    C:\Windows\Sysnative\drivers\bridge.sys
2015-03-04 19:33:31    0E046FF5823B95326D10CF1B4AF23541    39424    ----a-w-    C:\Windows\Sysnative\drivers\nsiproxy.sys
2015-03-04 19:33:29    807F8CF3E973305FC435C61CBBEE2A49    189248    -c--a-w-    C:\Windows\Sysnative\drivers\UCX01000.SYS
2015-03-04 19:33:27    5F66B7BB330AA80067FC66149A692620    33600    ----a-w-    C:\Windows\Sysnative\drivers\wimmount.sys
2015-03-04 19:33:27    2A2F8D5284E59815169A88F1FC9CEE28    51008    -c--a-w-    C:\Windows\Sysnative\drivers\mouclass.sys
2015-03-04 19:33:21    BC8A79C625568DDB7DCA49D0C2741A64    27456    ----a-w-    C:\Windows\Sysnative\drivers\rdpvideominiport.sys
2015-03-04 19:33:21    A57A897E3F87B8E9F30A627C42779A76    21824    ----a-w-    C:\Windows\Sysnative\drivers\tbs.sys
2015-03-04 19:33:09    5C8F604F6DC74177CDD8372D7B1ADFF0    212736    -c--a-w-    C:\Windows\Sysnative\drivers\usbvideo.sys
2015-03-04 19:32:47    DDD7F92A83F74D1476B71FBA9530A8DC    72192    ----a-w-    C:\Windows\Sysnative\drivers\ndproxy.sys
2015-03-04 19:32:29    D4DCE03870314D3354F3501F9DDD4123    87040    ----a-w-    C:\Windows\Sysnative\drivers\netvsc63.sys
2015-03-04 19:32:28    415DD71628795197F7AFC176CBADC74E    82944    ----a-w-    C:\Windows\Sysnative\drivers\appid.sys
2015-03-04 19:32:19    42FF4975D032CAE558AE4BB8448F6E5A    48128    ----a-w-    C:\Windows\Sysnative\drivers\netbios.sys
2015-03-04 19:32:00    13BEA6C882D4D877A5A85CA149C86BC1    40960    ----a-w-    C:\Windows\Sysnative\drivers\scfilter.sys
2015-03-04 19:31:56    D887446F3F6051C60C26F4FD1FC8D43F    107520    -c--a-w-    C:\Windows\Sysnative\drivers\i8042prt.sys
2015-03-04 19:31:56    D7A41959BB3A8510F1BAC36F5CEC1874    144384    ----a-w-    C:\Windows\Sysnative\drivers\rmcast.sys
2015-03-04 19:31:56    91223A2AE2955B3E0DA3DB79C3A897A6    30208    -c--a-w-    C:\Windows\Sysnative\drivers\mouhid.sys
2015-03-04 19:31:56    4A34D7084B862A92F3ABC4969166B3D3    32256    -c--a-w-    C:\Windows\Sysnative\drivers\kbdhid.sys
2015-03-04 19:31:55    96B01F117057FB4DAE0FF919ACB55770    26112    -c--a-w-    C:\Windows\Sysnative\drivers\sermouse.sys
2015-03-04 19:31:55    8CECC8DA55F3274181FD1EA28AD76664    43008    ----a-w-    C:\Windows\Sysnative\drivers\ndiscap.sys
2015-03-04 19:31:55    67343511D80BF3D6D9EEDB5BA8D0B06B    57856    -c--a-w-    C:\Windows\Sysnative\drivers\bthhfenum.sys
2015-03-04 19:31:55    51B3AC0560848CD6D65AC2033E293113    66560    ----a-w-    C:\Windows\Sysnative\drivers\mslldp.sys
2015-03-04 19:31:55    1104A31260CCF4318C884E0AE6C513BF    53248    -c--a-w-    C:\Windows\Sysnative\drivers\bthenum.sys
2015-03-04 19:31:54    B337B1F1E82A83E20A1743E008E25C0F    17408    ----a-w-    C:\Windows\Sysnative\drivers\rasacd.sys
2015-03-04 19:31:54    9746BA79DE0CA5EB5104406A9ED62D01    11776    ----a-w-    C:\Windows\Sysnative\drivers\rootmdm.sys
2015-03-04 19:31:54    83868EB2924E6BC21A54337C65D614D1    47104    ----a-w-    C:\Windows\Sysnative\drivers\qwavedrv.sys
2015-03-04 19:31:54    82821F4EEC776B4CF11695A38F3ABA46    24576    ----a-w-    C:\Windows\Sysnative\drivers\ndistapi.sys
2015-03-04 19:31:54    3083926D1CC5B56EA0786527B557DD1B    103424    ----a-w-    C:\Windows\Sysnative\drivers\Ndu.sys
2015-03-04 19:31:54    20185BEB7512EDE4EFECDFA148AC9F99    29696    -c--a-w-    C:\Windows\Sysnative\drivers\TsUsbGD.sys
2015-03-04 19:31:54    08EA90955AED2D959EE67DF6EDF0E2B6    81920    -c--a-w-    C:\Windows\Sysnative\drivers\BTHUSB.SYS
2015-03-04 19:31:54    0139248F6B95CF0D837B5B46A2722D40    98304    -c--a-w-    C:\Windows\Sysnative\drivers\usbcir.sys
2015-03-01 22:03:03    0EFD1C577BD6BC20A7FCD57CB5FB8C83    13211280    ----a-w-    C:\Windows\Sysnative\drivers\nvlddmkm.sys
2015-03-01 17:33:55    15C8C65CEA018C02EA0F648448C491C5    177984    ----a-w-    C:\Windows\Sysnative\drivers\ksecpkg.sys
2015-03-01 17:33:54    3930E508DDA46C1FF68FD963F350AA0A    563504    ----a-w-    C:\Windows\Sysnative\drivers\cng.sys
2015-03-01 17:33:04    DB32958F0E704EFBF7F15161A569E39F    140800    ----a-w-    C:\Windows\Sysnative\drivers\mrxdav.sys
2015-03-01 17:33:03    F0CB6DB513CAC393D04A0FCE0A59E1BF    75776    ----a-w-    C:\Windows\Sysnative\drivers\ahcache.sys
2015-03-01 17:32:58    B02118A776C368F7EE1A8CC81378D265    153920    -c--a-w-    C:\Windows\Sysnative\drivers\dumpsd.sys
2015-03-01 17:32:58    A770340FC02B999EF0DE6C2A6BC8437C    39744    -c--a-w-    C:\Windows\Sysnative\drivers\intelpep.sys
2015-03-01 17:32:58    7B7C482CF48E6EE33664340D1A78E6FE    238912    -c--a-w-    C:\Windows\Sysnative\drivers\sdbus.sys
2015-03-01 17:32:58    24A8DFC07E4BAF29AEA26E383D4CC886    86336    ----a-w-    C:\Windows\Sysnative\drivers\pdc.sys
2015-03-01 17:25:56    F2CD517CD62CCD51A94B65FBB7394D74    30408    ----a-w-    C:\Windows\Sysnative\drivers\nvpciflt.sys
2015-03-01 17:07:08    DE7ED58FFEB9AF0F7E2BFAF3C586A873    41824    ----a-w-    C:\Windows\Sysnative\drivers\dptf_acpi.sys
2015-03-01 17:07:08    C7BB8A4F62C7B23D4548B465688A1CCF    216360    ----a-w-    C:\Windows\Sysnative\drivers\esif_lf.sys
2015-03-01 17:07:08    4C1DDFC71179C642E86DB4A321724797    38720    ----a-w-    C:\Windows\Sysnative\drivers\dptf_cpu.sys
====== C:\Windows\Tasks ======
2015-03-28 18:27:07    A5C12DA18E831D1AF54462E78723CB8A    3124    ----a-w-    C:\Windows\Sysnative\Tasks\{94FE65F4-62B1-4473-8A87-BD71E63AF347}
2015-03-24 21:17:42    BB4833AE86E7E54086510612A6E57A4F    3718    ----a-w-    C:\Windows\Sysnative\Tasks\Adobe Flash Player Updater
2015-03-24 21:17:42    3ADDD66EB193D4859E9AEA378BFF444C    830    ----a-w-    C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-03-22 20:29:43    9473088D038CFF7606158DA05E154196    3182    ----a-w-    C:\Windows\Sysnative\Tasks\PCDoctorBackgroundMonitorTask-Retry
2015-03-21 21:19:52    --------    d-----w-    C:\Windows\Sysnative\Tasks\Apple
2015-03-10 20:56:30    C83DE58D46F322CE6E84B18F734631A1    4952    ----a-w-    C:\Windows\Sysnative\Tasks\Microsoft Office 15 Sync Maintenance for DAVESPC-David DavesPC
2015-03-06 23:47:50    D06B3476BE2815CEF8DA61092E3CE7D3    3376    ----a-w-    C:\Windows\Sysnative\Tasks\WINshell Event Notification
2015-03-06 23:47:50    522EE96E0ECFCA2681DABDB5438C96BD    3372    ----a-w-    C:\Windows\Sysnative\Tasks\WINshell Event Logging
2015-03-05 21:16:13    DB1009D2DCBCE4CA601F57BF9DAA981A    3590    ----a-w-    C:\Windows\Sysnative\Tasks\Dell SupportAssistAgent AutoUpdate
2015-03-01 21:18:32    C2F7936470024169D922B48A8F41A8BD    3504    ----a-w-    C:\Windows\Sysnative\Tasks\PCDEventLauncherTask
2015-03-01 21:18:32    9B5E06CCE9ADF6A12095D7DFB45E64F4    4048    ----a-w-    C:\Windows\Sysnative\Tasks\PCDoctorBackgroundMonitorTask
2015-03-01 21:18:31    7F13A6575EFB971D2558B73BA25D5331    3226    ----a-w-    C:\Windows\Sysnative\Tasks\SystemToolsDailyTest
====== C:\Windows\Temp ======
======= C:\Program Files =====
2015-03-24 18:56:31    --------    d-----w-    C:\Program Files\Microsoft Silverlight
2015-03-21 21:20:33    --------    d-----w-    C:\Program Files\iTunes
2015-03-21 21:20:33    --------    d-----w-    C:\Program Files\iPod
2015-03-21 21:19:43    --------    d-----w-    C:\Program Files\Bonjour
2015-03-21 21:19:38    --------    d-----w-    C:\Program Files\Common Files\Apple
2015-03-10 18:53:36    --------    d-----w-    C:\Program Files\Common Files\DESIGNER
2015-03-10 18:53:23    --------    d-----w-    C:\Program Files\Microsoft.NET
2015-03-10 18:52:43    --------    d-----w-    C:\Program Files\Microsoft SQL Server
2015-03-10 18:51:15    --------    d-----w-    C:\Program Files\Microsoft Analysis Services
2015-03-10 18:51:07    --------    d-----w-    C:\Program Files\Microsoft Office
2015-03-01 22:25:18    --------    d-----w-    C:\Program Files\Strogino CS Portal
2015-03-01 21:55:37    --------    d-----w-    C:\Program Files\Nexus Mod Manager
2015-03-01 17:25:39    --------    d-----w-    C:\Program Files\NVIDIA Corporation
======= C:\PROGRA~2 =====
2015-03-24 18:56:31    --------    d-----w-    C:\PROGRA~2\Microsoft Silverlight
2015-03-21 21:20:33    --------    d-----w-    C:\PROGRA~2\iTunes
2015-03-21 21:19:51    --------    d-----w-    C:\PROGRA~2\Apple Software Update
2015-03-21 21:19:43    --------    d-----w-    C:\PROGRA~2\Bonjour
2015-03-21 21:19:30    --------    d-----w-    C:\PROGRA~2\COMMON~1\Apple
2015-03-17 10:51:42    --------    d-----w-    C:\PROGRA~2\Free RAR Extract Frog
2015-03-16 17:16:53    --------    d-----w-    C:\PROGRA~2\Mozilla Maintenance Service
2015-03-10 18:53:23    --------    d-----w-    C:\PROGRA~2\Microsoft SQL Server
2015-03-10 18:51:15    --------    d-----w-    C:\PROGRA~2\Microsoft Analysis Services
2015-03-06 23:48:10    --------    d-----w-    C:\PROGRA~2\R.G. Mechanics
2015-03-05 21:16:05    --------    d-----w-    C:\PROGRA~2\Dell
2015-03-02 21:11:21    --------    d-----w-    C:\PROGRA~2\Ubisoft
2015-03-02 02:13:23    --------    d-----w-    C:\PROGRA~2\2K Games
2015-03-02 02:12:22    --------    d-----w-    C:\PROGRA~2\Elaborate Bytes
======= C: =====
====== C:\Users\David\AppData\Roaming ======
2015-03-23 23:11:52    --------    d-----w-    C:\Users\David\AppData\Local\Chromium
2015-03-23 23:10:14    --------    d-----w-    C:\Users\David\AppData\Local\The Lord of the Rings Online
2015-03-23 20:51:23    --------    d-----w-    C:\Users\David\AppData\Local\Akamai
2015-03-23 20:50:56    --------    d-----w-    C:\Users\David\AppData\Local\Turbine
2015-03-23 20:37:48    --------    d-----w-    C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Turbine
2015-03-23 20:37:17    --------    d-----w-    C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Happy Cloud
2015-03-22 20:17:24    --------    d-----w-    C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Microsoft
2015-03-21 21:20:51    --------    d-----w-    C:\Users\David\AppData\Roaming\Apple Computer
2015-03-21 21:20:51    --------    d-----w-    C:\Users\David\AppData\Local\Apple Computer
2015-03-21 21:19:52    --------    d-----w-    C:\Users\David\AppData\Local\Apple
2015-03-21 21:19:50    --------    d-----w-    C:\Windows\SysNative\config\systemprofile\AppData\Roaming\Apple Computer
2015-03-17 16:48:44    --------    d-----w-    C:\Users\David\AppData\Roaming\.mono
2015-03-17 16:48:43    --------    d-----w-    C:\Users\David\AppData\Roaming\Colossal Order
2015-03-17 16:48:43    --------    d-----w-    C:\Users\David\AppData\Local\Colossal Order
2015-03-17 10:51:48    --------    d-----w-    C:\Users\David\AppData\Roaming\Philipp Winterberg
2015-03-16 17:16:59    --------    d-----w-    C:\Users\David\AppData\Roaming\Mozilla
2015-03-16 17:16:59    --------    d-----w-    C:\Users\David\AppData\Local\Mozilla
2015-03-11 00:19:37    --------    d-----w-    C:\Windows\sysWoW64\config\systemprofile\AppData\Roaming\Adobe
2015-03-11 00:18:56    --------    d-----w-    C:\Windows\SysNative\config\systemprofile\AppData\Roaming\Adobe
2015-03-10 18:51:11    --------    d-----w-    C:\Users\David\AppData\Local\Microsoft Help
2015-03-10 11:20:05    --------    d-----w-    C:\Users\David\AppData\Roaming\Identities
2015-03-07 13:27:45    --------    d-----w-    C:\Users\David\AppData\Roaming\Sid Meier's Civilization 5
2015-03-02 21:11:29    --------    d-----w-    C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-03-02 21:11:29    --------    d-----w-    C:\Users\David\AppData\Local\Ubisoft Game Launcher
2015-03-02 02:27:27    --------    d-----w-    C:\Users\David\AppData\Local\My Games
2015-03-02 02:12:54    --------    d-----w-    C:\Users\David\AppData\Roaming\InstallShield
2015-03-01 22:35:27    --------    d-----w-    C:\Users\David\AppData\Locallow\Facepunch Studios LTD
2015-03-01 22:29:21    --------    d-----w-    C:\Users\David\AppData\Roaming\NVIDIA
2015-03-01 22:07:36    --------    d-----w-    C:\Users\David\AppData\Local\Skyrim
2015-03-01 22:07:11    --------    d-----w-    C:\Users\David\AppData\Local\Black_Tree_Gaming
2015-03-01 21:55:15    --------    d-----w-    C:\Users\David\AppData\Local\Programs
2015-03-01 21:15:12    --------    d-----w-    C:\Users\David\AppData\Roaming\PCDr
2015-03-01 17:27:32    --------    d-----w-    C:\Users\David\AppData\Local\NVIDIA
2015-03-01 16:21:42    --------    d-----w-    C:\Users\David\AppData\Roaming\DropboxOEM
2015-03-01 15:22:08    --------    d-----w-    C:\Users\David\AppData\Local\Steam
====== C:\Users\David ======
2015-03-28 18:30:20    31D2409237481996E00505054E68BA3E    21540440    ----a-w-    C:\Users\David\Downloads\mbam-setup-2.1.4.1018.exe
2015-03-28 18:25:49    E55CCE4E4A0153A3122E76A3DA23B288    2168320    ----a-w-    C:\Users\David\Downloads\AdwCleaner.exe
2015-03-28 13:13:31    F58676DE827DD9A5F3A44A698E8B4663    2095616    ----a-w-    C:\Users\David\Downloads\FRST64.exe
2015-03-28 13:11:31    67D890E8DA0A5DB2846B6366172D15A0    1135104    ----a-w-    C:\Users\David\Downloads\FRST.exe
2015-03-24 18:56:34    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-03-24 18:55:37    2EDE6612B7042D8582819CAB084E6883    13087456    ----a-w-    C:\Users\David\Downloads\Silverlight_x64.exe
2015-03-23 20:37:42    --------    d-----w-    C:\ProgramData\Turbine
2015-03-23 20:37:13    --------    d-----w-    C:\ProgramData\HappyCloud
2015-03-23 20:37:00    DB8F715B60AAA2FC5EFFE2E5B284C578    8711768    ----a-w-    C:\Users\David\Downloads\LOTROProgressive_4.28.exe
2015-03-23 19:00:04    700F4F94AB3449651F662C9FB94257B7    7515000    ----a-w-    C:\Users\David\Downloads\Xbox360_32Eng.exe
2015-03-21 21:20:49    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-03-21 21:20:33    --------    d-----w-    C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-03-21 21:20:33    --------    d-----w-    C:\ProgramData\Apple Computer
2015-03-21 21:19:30    --------    d-----w-    C:\ProgramData\Apple
2015-03-20 17:24:55    C3F4320F9A03E19CD9377299F41052F2    152428336    ----a-w-    C:\Users\David\Downloads\itunes6464setup.exe
2015-03-17 16:48:44    --------    d-----w-    C:\ProgramData\.mono
2015-03-17 10:51:42    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free RAR Extract Frog
2015-03-17 10:51:03    674452B9076213B0ADCFA4B2CD49DE56    1118048    ----a-w-    C:\Users\David\Downloads\InstallFreeRARExtractFrog.exe
2015-03-16 21:23:39    B5F5CA9976382056EFE7D015A525FCC1    5446736    ----a-w-    C:\Users\David\Downloads\avast_pro_antivirus_setup_online.exe
2015-03-16 17:16:54    --------    d-----w-    C:\ProgramData\Mozilla
2015-03-11 00:18:56    --------    d-----r-    C:\Windows\SysNative\config\systemprofile\Favorites
2015-03-10 18:53:57    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-03-10 18:51:06    --------    d-----w-    C:\ProgramData\Microsoft Help
2015-03-07 13:29:49    --------    d-----w-    C:\ProgramData\Steam
2015-03-07 13:27:46    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2015-03-05 21:16:20    --------    dc-h--w-    C:\ProgramData\{6AACA38B-2810-4B47-BDEC-D7A1F38B1531}
2015-03-05 21:16:05    --------    d-----w-    C:\ProgramData\SupportAssistAgent
2015-03-02 02:12:22    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2015-03-01 22:37:13    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strogino CS Portal
2015-03-01 21:55:39    --------    d-----w-    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2015-03-01 21:18:29    --------    d-----w-    C:\ProgramData\PC-Doctor for Windows
2015-03-01 17:26:31    --------    d-----w-    C:\ProgramData\NVIDIA
2015-03-01 16:41:00    E6897E8CF8453750DEB91B2D62096425    103832    ----a-w-    C:\Users\David\GoToAssistDownloadHelper.exe

====== C: exe-files ==
2015-03-28 19:01:47    26793BC0B998B3595F1FA5D7A0C16923    183816    ----a-w-    C:\WINDOWS\Temp\DPTF\esif_assist.exe
2015-03-28 18:30:20    31D2409237481996E00505054E68BA3E    21540440    ----a-w-    C:\Users\David\Downloads\mbam-setup-2.1.4.1018.exe
2015-03-28 18:25:49    E55CCE4E4A0153A3122E76A3DA23B288    2168320    ----a-w-    C:\Users\David\Downloads\AdwCleaner.exe
2015-03-28 13:13:31    F58676DE827DD9A5F3A44A698E8B4663    2095616    ----a-w-    C:\Users\David\Downloads\FRST64.exe
2015-03-28 13:11:31    67D890E8DA0A5DB2846B6366172D15A0    1135104    ----a-w-    C:\Users\David\Downloads\FRST.exe
2015-03-28 12:50:23    D41D8CD98F00B204E9800998ECF8427E    0    ----a-w-    C:\WINDOWS\ServiceProfiles\NetworkService\AppData\Local\Temp\mpam-a23a31e5.exe
2015-03-28 00:16:58    049C147AC051172E834B396875C3A5D8    8358720    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe
2015-03-28 00:16:57    F0D5F6A9CC9FD1F2457B36A8771DDD30    1108624    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe
2015-03-28 00:16:57    D069702CA43FC9AEA4FE74681BC1311F    895176    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NvStereoUtilityOGL.exe
2015-03-28 00:16:57    CF39EA4820892171C40DD07611F7FA8E    2612224    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvsttest.exe
2015-03-28 00:16:57    704DFF699CF979DF6854ED442F87C25B    616592    ----a-w-    C:\WINDOWS\SysWOW64\nvStreaming.exe
2015-03-28 00:16:57    3C2FE5A041D0C865C587DBFE215F087F    833736    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvStInst.exe
2015-03-28 00:16:57    37D3001556030C20DCBB652608CFFE20    411968    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
2015-03-28 00:16:57    11AF705F760D8776D2230C29D7B1EACE    1910080    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe
2015-03-28 00:16:57    0576419583CEE689739E3178D6A9F4CD    437576    ----a-w-    C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstreg.exe
2015-03-27 20:38:37    BCB7868153F63BD77B6259FD431304BB    441912    ----a-w-    C:\Users\David\AppData\Local\NVIDIA\NvBackend\Packages\000072b7\CoProc update.19440473.exe
2015-03-27 19:40:07    F32F71DD831543D3C90FBC1EC1D3A291    18665696    ----a-w-    C:\Program Files (x86)\Steam\SteamApps\downloading\252490\RustClient.exe
2015-03-27 19:40:02    5317D001B40EAF91ECA71644F1B984C6    836288    ----a-w-    C:\Program Files (x86)\Common Files\Steam\SteamServiceTmp.exe
2015-03-25 20:37:06    444EA843E5945BAF8E9AB0DA2E3FD09F    440440    ----a-w-    C:\Users\David\AppData\Local\NVIDIA\NvBackend\Packages\0000729d\CoProc update.19433226.exe
2015-03-25 19:44:02    F22794B93C9FC55A934C1544F9600B43    70832    ----a-w-    C:\WINDOWS\System32\CompatTel\diagtrackrunner.exe
2015-03-24 21:21:37    21319BC6D418B1F5366EBF41A4BDA979    28180048    ----a-w-    C:\Games\Middle-earth Shadow of Mordor\x64\ShadowOfMordor.exe
2015-03-24 21:21:37    18D2E4A98110C4825E59A563181B41AD    360275    ----a-w-    C:\Games\Middle-earth Shadow of Mordor\x64\Launcher.exe
2015-03-24 18:55:37    2EDE6612B7042D8582819CAB084E6883    13087456    ----a-w-    C:\Users\David\Downloads\Silverlight_x64.exe
2015-03-23 20:51:36    1B34EF0654A5BDF63CC2C4D39503A504    4570000    ----a-w-    C:\Users\David\AppData\Local\Akamai\ControlPanel.exe
2015-03-23 20:51:31    C3CF44311AF5257CB6054897D35173E1    10475384    ----a-w-    C:\Users\David\AppData\Local\Akamai\netsession_installer.exe
2015-03-23 20:40:38    605C5E8026AAC88783A3E68635DED621    1350104    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineLauncher.exe
2015-03-23 20:40:38    2A61949CA94C3787A942770D7EDF4280    1233368    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\backup\TurbineLauncher.exe
2015-03-23 20:40:36    88A34134F33BA0185B79488D5E1ED738    1128408    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\turbineclientlauncher.exe
2015-03-23 20:40:36    7C51AF0929083703C01102BEB4D0DA44    1116120    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\backup\turbineclientlauncher.exe
2015-03-23 20:40:15    3DD1832B1E146BA2DADE13989760E635    25112576    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\lotroclient.exe
2015-03-23 20:40:15    063866BA914D8481635B0B0AE69D49F2    25010176    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\backup\lotroclient.exe
2015-03-23 20:40:07    CE2922F83FB4B170AFFCE0EA448B107B    2707352    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\Installer\vcredist_x86.exe
2015-03-23 20:40:07    5C82BE7AD1775B67916EE19C15B99331    2723264    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\Installer\vcredist_x86_VC8_SP1.exe
2015-03-23 20:39:57    8C0C64D42825BE2F29D3A656F558AD46    6315559    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\Installer\dx9-2009-8-v3.exe
2015-03-23 20:39:49    B88228D5FEF4B6DC019D69D4471F23EC    5073240    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\Installer\vcredist_x86-2010.exe
2015-03-23 20:39:45    68B3E92A955548CE566C86AA3DAA8F23    8735554    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\Installer\dx9-2009-8-v2.exe
2015-03-23 20:38:41    D38B064A7831BE67D10FDC5F39E3B57E    961531    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\unins000.exe
2015-03-23 20:38:28    D1A6D7F44BC99CEDDD5B5BE0B7628ACD    541968    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineRegisterGDF.exe
2015-03-23 20:38:28    3DA452BB4D88A409F413509C65EEECCE    210192    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\CleanUninstall.exe
2015-03-23 20:38:28    313E12B63831FF30858C1329A4C8BF26    453432    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\AwesomiumProcess.exe
2015-03-23 20:38:28    238CE1BF1700B7A437923A3D80BA062A    46352    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineElevator.exe
2015-03-23 20:38:28    1D26CDA05800CDB84E590F1BFAF10FCC    210704    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineInvoker.exe
2015-03-23 20:37:48    3E53E49E6D74E5C06F65FF84801E0B0B    692632    ----a-w-    C:\ProgramData\Turbine\The Lord of the Rings Online\hcuninstaller.exe
2015-03-23 20:37:17    E833219B1EF0EA2F6E2C18D0D31EEB62    397520    ----a-w-    C:\ProgramData\HappyCloud\Application\uninstaller.exe
2015-03-23 20:37:16    B3054118D70639FAEF382E924FE032C5    4586848    ----a-w-    C:\ProgramData\HappyCloud\Application\HappyCloudService.exe
2015-03-23 20:37:16    637AB561401A53662FCC6C3962184D44    705376    ----a-w-    C:\ProgramData\HappyCloud\Application\hcwebwindow.exe
2015-03-23 20:37:16    3E53E49E6D74E5C06F65FF84801E0B0B    692632    ----a-w-    C:\ProgramData\HappyCloud\Application\hcuninstaller.exe
2015-03-23 20:37:16    103E44ED5E1AE37CD97193F09D2AD24D    755104    ----a-w-    C:\ProgramData\HappyCloud\Application\hcfwexcp.exe
2015-03-23 20:37:00    DB8F715B60AAA2FC5EFFE2E5B284C578    8711768    ----a-w-    C:\Users\David\Downloads\LOTROProgressive_4.28.exe
2015-03-23 19:00:04    700F4F94AB3449651F662C9FB94257B7    7515000    ----a-w-    C:\Users\David\Downloads\Xbox360_32Eng.exe
=== C: other files ==
2015-03-28 19:07:05    98E5C7CDDF35087DC9FB259557CF6592    68451    ----a-w-    C:\Users\David\Desktop\FRST.zip
2015-03-28 18:32:49    E9CD058C79EA15B4AA93E259FA713B07    136408    ----a-w-    C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys
2015-03-28 18:31:04    CF12E148C6FC151335B7D7FE03F1C7A2    25816    ----a-w-    C:\WINDOWS\System32\drivers\mbam.sys
2015-03-28 18:31:04    7FD0FDFB97D80B21195273C4C3810FE1    64216    ----a-w-    C:\WINDOWS\System32\drivers\mwac.sys
2015-03-28 18:31:04    68C3B11D1ED8C97648BEEFEC37E93E74    107736    ----a-w-    C:\WINDOWS\System32\drivers\mbamchameleon.sys
2015-03-28 18:28:40    B9FB1394C3537BFC87AEEF8C0AA6E1CE    101    ----a-w-    C:\Users\David\AppData\Local\Temp\utt85BD.tmp.bat
2015-03-28 18:28:08    F2F18BC5529FFD6B9B22B18972E10202    68    ----a-w-    C:\Users\David\AppData\Local\Temp\HYD6E7.tmp.1427567288\HTA\install.1427567288.zip
2015-03-28 18:27:51    F2F18BC5529FFD6B9B22B18972E10202    68    ----a-w-    C:\Users\David\AppData\Local\Temp\HYDC6A2.tmp.1427567271\HTA\install.1427567271.zip
2015-03-28 18:26:42    F2F18BC5529FFD6B9B22B18972E10202    68    ----a-w-    C:\Users\David\AppData\Local\Temp\HYDB939.tmp.1427567202\HTA\install.1427567202.zip
2015-03-28 13:47:11    9852F5F733CFDADC43680FAE2A8C224D    68114    ----a-w-    C:\Users\David\Downloads\FRST.zip
2015-03-25 19:29:31    C8377A82D60BE9ABEB89B8504268028A    1746967707    ----a-w-    C:\Users\David\Downloads\Automation.The.Car.Company.Tycoon.Game.Build.150315.zip
2015-03-24 21:21:38    F3694895AC18B37FA405CF3F8CE877A6    226    ----a-w-    C:\Games\Middle-earth Shadow of Mordor\x64\update-MiddleEarth.bat
2015-03-24 21:21:38    5C2B8C97A4473B4B3B4D74E0C5E58324    226    ----a-w-    C:\Games\update-MiddleEarth.bat
2015-03-24 21:21:36    F3694895AC18B37FA405CF3F8CE877A6    226    ----a-w-    C:\Games\Middle-earth Shadow of Mordor\update-MiddleEarth.bat

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\ixfac9rl.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\ixfac9rl.default
- Reddit Enhancement Suite - %ProfilePath%\extensions\jid1-xUfzOsOFlzSOXg@jetpack.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Default - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

==== Firefox Plugins ======================

Profilepath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\ixfac9rl.default
43583AB4DFD406F4C188342F41B1F91C    - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_134.dll -    Shockwave Flash
4C07B5286D129DFD25C24B4A31B9B888    - C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll -    Happy Cloud Plugin


==== Chromium Look ======================


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wny_wnzp_15_08&param1=1&param2=f%253D1%26b%3D{browser}%26cc%3Dus%26pa%3DWinYahoo%26cd%3D2XzuyEtN2Y1L1Qzu0A0E0DtC0BzzyCtBtAyC0E0B0C0AyByCtN0D0Tzu0StCtCyEyBtN1L2XzutAtFyBtFyCtFtCtN1L1CzutN1L1G1B1V1N2Y1L1Qzu2StCyCtDyBtCyEtBtAtG0AtAyEtBtGtA0B0BzztGyDtC0EzztGtAyE0ByC0A0E0Fzy0F0BtB0B2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyDtA0EtAtCzz0BzytGyC0CtA0FtGyEtA0E0EtGzz0BtBzztG0EzyyDyEyDyDtD0Fzzzz0FyB2Q%26cr%3D404889505%26a%3Dwny_wnzp_15_08%26os%3DWindows 8.1"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.com"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
{012E1000-F331-11DB-8314-0800200C9A66} Google  Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing  Url="http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC"
{165483AE-FABE-4C69-BB04-4511A3B8DCFF} Unknown  Url="Not_Found"

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\{165483AE-FABE-4C69-BB04-4511A3B8DCFF} deleted successfully
HKEY_USERS\S-1-5-21-2166885784-2345378379-971481276-1001\Software\Microsoft\Internet Explorer\SearchScopes\{165483AE-FABE-4C69-BB04-4511A3B8DCFF} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{165483AE-FABE-4C69-BB04-4511A3B8DCFF} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{165483AE-FABE-4C69-BB04-4511A3B8DCFF} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\David\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\David\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\David\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\David\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\David\AppData\Local\Mozilla\Firefox\Profiles\ixfac9rl.default\cache2 emptied successfully

==== Empty Chrome Cache ======================

No Chrome User Data found

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=883 folders=410 174132953 bytes)

==== Empty Temp Folders ======================

C:\Users\David\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\David\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on Mon 03/30/2015 at 10:00:28.90 ======================
 



#10 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:16 PM

Posted 30 March 2015 - 11:19 AM


Step 1

Please downloadesetlogo.pngOnline Scanner and save it to your Desktop.
  • Disable the realtime-protection of your antivirus and anti-malware programs because they might interfere with the scan.
  • Start installer.pngwith administartor privileges.
  • Select the option Yes, I accept the Terms of Use and click on Start.
  • Choose the following settings:
settings.png
  • Click on Start. The virus signature database will begin to download. This may take some time.
  • When completed the Online Scan will begin automatically.
    Note: This scan might take a long time! Please be patient.
  • When completed select Uninstall application on close if you so wish, but make sure you copy the logfile first!
  • Now click on Finish
  • A log filelog.pngis created at logpath.png
    Copy and paste the content of this log file in your next reply.
esetlog.png
Note: Do not forget to re-enable your antivirus application after running the above scan!
eset.gif
regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png

#11 deeprybka

deeprybka

  • Malware Response Team
  • 5,198 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:16 PM

Posted 04 April 2015 - 03:49 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
regards,
deeprybka
:busy:
Neminem laede, immo omnes, quantum potes, iuva. Arthur Schopenhauer
 
unite_blue.png
asap.png




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users