start
CreateRestorePoint:
CloseProcesses:
Task: {0E54B70A-72D5-4895-BAEB-EEC3A9254D69} - \{C324077E-E3A0-4BEE-822C-B7C7A9DD550E} -> No File <==== ATTENTION
Task: {120126EA-8369-4B3E-88B4-8B0D869DB2D1} - \G2MUpdateTask-S-1-5-21-1324307301-759359316-4020353428-1000 -> No File <==== ATTENTION
Task: {1AB12998-945B-49A8-AB0F-69DCB4B881E7} - \Microsoft_Hardware_Launch_itype_exe -> No File <==== ATTENTION
Task: {1CCE14E9-61A7-4EF6-8D0A-C3E9467FB995} - \CreateChoiceProcessTask -> No File <==== ATTENTION
Task: {26F53C62-445E-4D9A-8DE3-A42DE6269C95} - \SUPERAntiSpyware Scheduled Task 8d0590c2-ae5f-4aef-be2d-16065f46532b -> No File <==== ATTENTION
Task: {279A2790-CA57-459A-9B28-4713BEBE3E08} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {3A4971E5-F6C3-4CBA-88DE-3F42DEF05DC2} - \{8A7D90B1-09CD-4C82-99D5-54C8078B0E82} -> No File <==== ATTENTION
Task: {73B6390C-1FBF-43D7-8649-425735D100A9} - \{E2E39917-7B53-4470-897C-3E8EBCE124E6} -> No File <==== ATTENTION
Task: {88AED461-B2A0-44D8-B15E-F7026FC698F2} - \Java Platform SE Auto Updater -> No File <==== ATTENTION
Task: {8C247B5C-2AF3-47ED-8E25-A875DB3C0516} - \GoogleUpdateTaskMachineUA -> No File <==== ATTENTION
Task: {93598228-D60D-42AB-9D65-A99EF86079FE} - \{9CA7D29C-249C-4CD2-989F-C0417082083D} -> No File <==== ATTENTION
Task: {A4E00632-5E5F-4E60-B9B0-BAE099446467} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {A69314E2-611C-43EC-9EDF-E2DE106CA7E2} - \Microsoft_Hardware_Launch_mousekeyboardcenter_exe -> No File <==== ATTENTION
Task: {AAC5EBDB-ED17-42AC-A0D9-89822F934272} - \WebReg Officejet 6500 E709a Series -> No File <==== ATTENTION
Task: {B09FDB7E-32C6-4F3F-9599-E76B4580AF74} - \DropboxUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {B787BA2A-6F83-4464-86DC-E84284980B30} - \Microsoft_Hardware_Launch_ipoint_exe -> No File <==== ATTENTION
Task: {BE52805A-EBAA-43B9-976B-5BCB67ED2921} - \G2MUploadTask-S-1-5-21-1324307301-759359316-4020353428-1000 -> No File <==== ATTENTION
Task: {CB71A058-ABDB-4F45-8201-C02B7052A1CB} - \SUPERAntiSpyware Scheduled Task 504be6ac-4f4e-4e4c-bbd2-771cbd7824f9 -> No File <==== ATTENTION
Task: {D2092D79-28AE-4C52-B039-E59AEA8EC3DD} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {D9329535-94CE-4F48-9F7F-A6D0A6DFACBF} - \Microsoft_MKC_Logon_Task_itype.exe -> No File <==== ATTENTION
Task: {DDC977ED-9853-40AC-9C05-8A5EFBBCE651} - \GoogleUpdateTaskMachineCore -> No File <==== ATTENTION
Task: {DE04F873-BA91-41DE-B2BA-1A399D6685FB} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {E252CF8C-56AD-41CF-A395-8C291CC907FB} - \{3D9D960B-DB71-42A9-BE0D-7DD16AB608ED} -> No File <==== ATTENTION
Task: {FAF5ED7B-589E-46C5-88E4-B7C7A723EABE} - \{BC4DAC18-9546-4621-93ED-A2AE9200F9D7} -> No File <==== ATTENTION
ShortcutWithArgument: C:\Users\Frithjof\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Silverlight Controls Browser.lnk -> C:\Users\Frithjof\AppData\LocalLow\Microsoft\Silverlight\OutOfBrowser\3163075259.
http://www.silverlight.net\316307525...rlight.net.ico () -> 3163075259.
www.silverlight.net
AlternateDataStreams: C:\ProgramData\TEMP:31D9EFCC [149]
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [119]
AlternateDataStreams: C:\Users\Frithjof\Downloads\esetsmartinstaller_deu(2).exe:BDU [0]
AlternateDataStreams: C:\Users\Frithjof\Downloads\F-SecureOnlineScanner(1).exe:BDU [0]
AlternateDataStreams: C:\Users\Frithjof\Downloads\F-SecureOnlineScanner.exe:BDU [0]
AlternateDataStreams: C:\Users\Frithjof\Downloads\OBS-Studio-0.14.2-Installer.exe:BDU [0]
AlternateDataStreams: C:\Users\Frithjof\Downloads\wlsetup3528-all - Copy.exe:BDU [0]
AlternateDataStreams: C:\Users\Frithjof\Downloads\wlsetup3528-all.exe:BDU [0]
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about_:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about_:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1324307301-759359316-4020353428-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?PC=AV01
HKU\S-1-5-21-1324307301-759359316-4020353428-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com/?PC=AV01
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1324307301-759359316-4020353428-1000 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-1324307301-759359316-4020353428-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
BHO: No Name -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2016-01-07] [not signed]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-01-07] [not signed]
FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} [2016-01-07] [not signed]
CHR DefaultSearchURL: Default -> hxxp://pandasecurity.mystart.com/results.php?searchsource=omnibar&pr=vmn&id=pandasecuritytb&v=2_3&ent=ds_671&q={searchTerms}
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
HKLM-x32\...\Run: [] => [X]
C:\ProgramData\hwjqxkkr.zva
C:\Users\Frithjof\AppData\Local\Temp\dllnt_dump.dll
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: bitsadmin /reset /allusers
EmptyTemp:
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
End