Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Malware bei Facebook

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 09.07.2015, 02:11   #1
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo, ich habe das gleiche Problem wie der User Susi16.

Ich gebe mal folgende Infos, vielleicht helfen sie weiter.

Ich vermute, dass es sich um eine Facebook-Pishingseite handelt.

Ich wollte mich über den Firefox in Facebook einloggen und es erscheint folgender Seitenname:

https:// www.facebook.com/?_rdr


?_rdr macht mich sehr stutzig,


normal klickt man dann drauf und dann kommt das mit dem Checkpoint, dass eine Malware auf dem PC gefunden wurde!

Man wird dann aufgefordert, entweder von Kaspersky oder F Secure ein Malwareprogramm runterzuladen.

Es sind natürlich exe Dateien unter gleicher Adresse.

Ich lade da natürlich nichts runter. Ich habe einen Screenshot gemacht, da kann man genau die Adresse sehen, wo es runtergeladen werden soll.

Ich kann mich übrigens über Opera und Google Chrome ganz normal in Facebook einloggen, dass Problem ist nur mit Firefox, denn ich schon neu installiert habe und das Problem mit Facebook bleibt bestehen. Das Problem ist an einem anderen Pc auch nicht, nur bei mir über Firefox.

Was ist denn da los? Handelt es sich defintiv um eine Pishingseite?
Wie bekomme ich Firefox wieder sauber, ich vermute, da stimmt etwas nicht.



Ich habe mal danach gesucht: AKAMAIHD

Das ist doch ein Virus!

Adwc Cleaner hat ihn nicht gefunden, Kaspersky und

Malwarebytes ebenfalls nicht!





Viele Grüße

Michelle



Das ist der Screenshot:


Geändert von michelle80 (09.07.2015 um 03:08 Uhr)

Alt 09.07.2015, 08:05   #2
schrauber
/// the machine
/// TB-Ausbilder
 

Malware bei Facebook - Standard

Malware bei Facebook



hi,

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)

__________________

__________________

Alt 09.07.2015, 10:57   #3
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo Schrauber,

vielen lieben Dank für deine schnelle Hilfe.
Ich habe den Scan soeben gemacht.



FRST Logfile:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by lxxxxx (administrator) on Lxxxxx-PC on 09-07-2015 10:50:46
Running from C:\Users\lxxxxx\Downloads
Loaded Profiles: lxxxxx &  (Available Profiles: laxxxxx & _supereasy_1cbackup_)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
() C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC
HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL
HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] ()
HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] ()
Startup: C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
BootExecute: autocheck autochk *  

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( )
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( )
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF SearchPlugin: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\searchplugins\ecosia.xml [2015-05-29]
FF Extension: PAYBACK Toolbar - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\toolbar-ff@payback.de.xpi [2014-12-10]
FF Extension: Ecosia — The search engine that plants trees! - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2014-06-27]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-03]

Chrome: 
=======
CHR Profile: C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03]
CHR Extension: (Google Drive) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03]
CHR Extension: (YouTube) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03]
CHR Extension: (Google Search) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03]
CHR Extension: (Safe Money) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03]
CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03]
CHR Extension: (Virtual Keyboard) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03]
CHR Extension: (Gmail) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03]
CHR Extension: (Anti-Banner) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 supereasy_1cbackup; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices)
R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm))
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-09 10:49 - 2015-07-09 10:49 - 02112512 _____ (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe
2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT.exe
2015-07-09 04:22 - 2015-07-09 04:22 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe
2015-07-09 03:22 - 2015-07-09 04:16 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_lazzyy
2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\ProductData
2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\ProductData
2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit
2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxxx\Downloads\iobituninstaller4.3.0.122.exe
2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxxx\Downloads\rkill.exe
2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys
2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe
2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0.exe
2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxxx\Downloads\revosetup95 (1).exe
2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe
2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207.exe
2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure
2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxxx\Desktop\F-SecureOnlineScanner.exe
2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\F-Secure
2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxxx\Desktop\de-de.setup.exe
2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys
2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat
2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxxx\Desktop\IMG-20150701-WA0000.jpeg
2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxxx\Desktop\smil.xml
2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys
2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys
2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys
2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys
2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\mresreg
2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxxx\Desktop\diasetup.exe
2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2
2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI
2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg
2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\lxxxxx\Desktop\fotoworks_setup.exe
2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxxx\Desktop\bilder-27062015-0224.zip
2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxxx\Bilder von Jxxxx xxxxx
2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys
2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys
2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys
2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys
2015-06-13 01:23 - 2015-06-13 01:23 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-12 15:41 - 2015-06-12 15:41 - 00017174 _____ C:\Users\lxxxxx\Documents\coolpad.odt
2015-06-11 14:42 - 2015-06-11 15:52 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1D534D16.sys
2015-06-10 15:53 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 15:53 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 15:53 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 15:53 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 15:53 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 15:53 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-06-10 15:53 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-06-10 15:53 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-06-10 15:53 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-06-10 15:53 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-06-10 15:53 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-06-10 15:53 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-06-10 15:53 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-06-10 15:53 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-06-10 15:53 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 15:53 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-06-10 15:53 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-06-10 15:53 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 15:53 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 15:53 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 15:53 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 15:53 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 15:53 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 15:53 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-06-10 15:53 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-06-10 15:53 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-06-10 15:52 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 15:52 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 15:52 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 15:52 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-10 15:51 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 15:51 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 15:51 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 15:51 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 15:51 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-06-10 15:51 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 15:51 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-06-10 15:51 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-06-10 15:51 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 15:51 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-06-10 15:51 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 15:51 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-06-10 15:51 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-06-10 15:51 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-06-10 15:51 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 15:51 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-06-10 15:51 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 15:51 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-06-10 15:51 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-06-10 15:51 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-06-10 15:51 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 15:51 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 15:51 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 15:51 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 15:51 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 15:51 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-06-10 15:51 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 15:51 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 15:51 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 15:51 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 15:51 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 15:51 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 15:51 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 15:51 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 15:51 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 15:51 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 15:51 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 15:51 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 15:51 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 15:51 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 15:51 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 15:51 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 15:51 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 15:51 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 15:51 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 15:51 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 15:51 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 15:51 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 15:51 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 15:51 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 15:51 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 15:51 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 15:51 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 15:51 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 15:51 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 15:51 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 15:51 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 15:51 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 15:51 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 15:51 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 00:39 - 2015-06-10 00:39 - 00013412 _____ C:\Users\lxxxxxx\Documents\michaxxxxxxxxxxxx.odt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-09 10:50 - 2014-06-12 09:00 - 00022046 _____ C:\Users\lxxxxx\Downloads\FRST.txt
2015-07-09 10:50 - 2014-06-12 08:59 - 00000000 ____D C:\FRST
2015-07-09 10:45 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-09 10:45 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job
2015-07-09 10:45 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-09 10:45 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-09 10:44 - 2014-06-05 15:51 - 00056806 _____ C:\Windows\setupact.log
2015-07-09 10:44 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini
2015-07-09 10:44 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-09 10:44 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-09 05:07 - 2014-06-02 10:56 - 01900281 _____ C:\Windows\WindowsUpdate.log
2015-07-09 04:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-09 04:25 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-09 04:25 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-09 04:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-09 04:18 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat
2015-07-09 04:18 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat
2015-07-09 04:18 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia
2015-07-09 04:11 - 2014-06-06 03:18 - 00019030 _____ C:\Windows\PFRO.log
2015-07-09 03:02 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner
2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_
2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-09 01:25 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxxx\Desktop\Revo Uninstaller.lnk
2015-07-09 01:25 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxxxab April 2015
2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxx\Bxxxxx ab Mai 2015 unbearbeitet
2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxxxBilder xxxxxxxxxxx
2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxxx\Bildervonxxxxxxxxx
2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontoxxxxx
2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontoxxxxx
2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxxxxxxx
2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxx von xxxxxxx
2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\VirtualStore
2015-06-27 02:14 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxxx
2015-06-27 01:18 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-06-27 01:18 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-06-27 01:18 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-06-26 01:47 - 2014-06-06 03:27 - 00000000 ____D C:\xxxxxxxxx
2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726
2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera
2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxxx\Formular für  xxxxxxxxx
2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxx\Documents xxxxxxx.odt
2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxxxxx2015
2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\Adobe
2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\Adobe
2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe
2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle
2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxx\Desktop\jxpiinstall.exe
2015-06-13 01:23 - 2014-06-03 15:47 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-10 22:29 - 2009-07-14 06:45 - 00296104 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-10 22:27 - 2014-12-10 06:09 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-10 22:27 - 2014-06-05 03:10 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-10 22:27 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 16:06 - 2014-03-13 13:01 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 16:02 - 2014-03-13 13:01 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-10 15:30 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Files in the root of some directories =======

2015-05-15 03:15 - 2015-05-17 00:13 - 0001062 _____ () C:\Users\lxxxxx\AppData\Local\998087a8e589f390f0b710fed8b8c1bf
2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\lxxxxx\cc_20140606_180858.reg


Some files in TEMP:
====================
C:\Users\lxxxxx\AppData\Local\Temp\Quarantine.exe
C:\Users\lxxxxx\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-04 15:15

==================== End of log ============================
         
--- --- ---






FRST Additions Logfile:
[CODE]Additional
FRST Logfile:
Code:
ATTFilter
scan result of Farbar Recovery Scan Tool (x64) Version:05-07-2015
Ran by lxxxxx at 2015-07-09 11:01:44
Running from C:\Users\lxxxxx\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-479257388-3634607433-1617756106-500 - Administrator - Disabled)
Gast (S-1-5-21-479257388-3634607433-1617756106-501 - Limited - Enabled)
lxxxxx (S-1-5-21-479257388-3634607433-1617756106-1001 - Administrator - Enabled) => C:\Users\lxxxxx
_supereasy_1cbackup_ (S-1-5-21-479257388-3634607433-1617756106-1002 - Administrator - Enabled) => C:\Users\_supereasy_1cbackup_

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

A1-Faktura 1.429 (HKLM-x32\...\A1-Faktura_is1) (Version:  - A1-Faktura)
AAVUpdateManager (HKLM-x32\...\{AFA42FE1-A5C3-485F-9180-BFCF5BF1F1C3}) (Version: 18.00.0000 - Wolters Kluwer Deutschland GmbH)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Adobe Flash Player 17 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 17.0.0.191 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.203 - Adobe Systems Incorporated)
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0407-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Shockwave Player 12.1 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.1.1.151 - Adobe Systems, Inc.)
AMD Catalyst Install Manager (HKLM\...\{82DEBC0B-5BAD-5918-2EDB-7C78BE01BA59}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Ashampoo Music Studio 4 v.4.1.2 (HKLM-x32\...\{91B33C97-7650-0EB0-B6C7-DDBA2932B7B4}_is1) (Version: 4.1.2 - Ashampoo GmbH & Co. KG)
Ashampoo Photo Converter 2 v.2.0.0 (HKLM-x32\...\{C92AB6F1-5566-A904-B32C-720C3BA1A819}_is1) (Version: 2.0.0 - Ashampoo GmbH & Co. KG)
CCleaner (HKLM\...\CCleaner) (Version: 4.14 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.4.4852 - CDBurnerXP)
COLOR projects premium (64-Bit) (HKLM\...\COLOR_PROJECTS_1_2_C935FDA1_is1) (Version: 1.14 - Franzis Verlag GmbH)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DriverEasy 4.9.0 (HKLM\...\DriverEasy_is1) (Version: 4.9.0.0 - Easeware)
Fotogalerie (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Glary Utilities 5.1 (HKLM-x32\...\Glary Utilities 5) (Version: 5.1.0.4 - Glarysoft Ltd)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 43.0.2357.132 - Google Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet 6700 - Grundlegende Software für das Gerät (HKLM\...\{9086D601-50B7-491D-A143-28193DADE36B}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Officejet 6700 Hilfe (HKLM-x32\...\{E1AE0CB7-1333-4728-8520-CB3F88A252B4}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP)
HP Photo Creations (HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\HP Photo Creations) (Version: 1.0.0.18332 - HP)
HP Photo Creations (HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\HP Photo Creations) (Version: 1.0.0.18332 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
HPOJ6700FWUpdateAlert (x32 Version: 1.00.0000 - HP) Hidden
HWiNFO64 Version 4.40 (HKLM\...\HWiNFO64_is1) (Version: 4.40 - Martin Malík - REALiX)
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 4.3.0.122 - IObit)
Java 7 Update 75 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F03217075FF}) (Version: 7.0.750 - Oracle)
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden
K-Lite Codec Pack 6.0.4 (Basic) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 6.0.4 - )
Malwarebytes Anti-Malware Version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\OneDriveSetup.exe) (Version: 17.0.4035.0328 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft_VC100_CRT_x86 (HKLM-x32\...\{6FDDB201-2CA0-42BD-973F-7B2C4A61EA3F}) (Version: 1.0.0 - Microsoft)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 39.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 39.0 (x86 de)) (Version: 39.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 39.0 - Mozilla)
Mozilla Thunderbird 31.7.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.7.0 (x86 de)) (Version: 31.7.0 - Mozilla)
OpenOffice 4.1.0 (HKLM-x32\...\{E19483E2-6C18-494D-A307-D4498BCFD2C7}) (Version: 4.10.9764 - Apache Software Foundation)
Opera Stable 30.0.1835.88 (HKLM-x32\...\Opera 30.0.1835.88) (Version: 30.0.1835.88 - Opera Software)
phonostar-Player Version 3.03.6 (HKLM-x32\...\phonostar3RadioPlayer_is1) (Version:  - )
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
PicPick (HKLM-x32\...\PicPick) (Version: 3.3.3 - NTeWORKS)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.75.827.2013 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7071 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
SIW version 2011.10.29 (HKLM-x32\...\{AB67580-257C-45FF-B8F4-C8C30682091A}_is1) (Version: 2011.10.29 - Topala Software Solutions)
StarMoney (x32 Version: 4.0.4.16 - StarFinanz) Hidden
StarMoney 9.0  (HKLM-x32\...\{5ACFB561-1610-47FC-8560-3476A99436A1}) (Version: 9.0 - Star Finanz GmbH)

Studie zur Verbesserung von HP Officejet 6700 Produkten (HKLM\...\{4EE2A4CB-47B0-4412-808C-D556E3940598}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.00 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH)
WinSysClean X5 (HKLM-x32\...\WinSysClean X5) (Version: 15.01 - Ultimate Systems, Inc.)
WinSysClean X5 (Version: 15.01 - Ultimate Systems, Inc.) Hidden


==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\lazzyy\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\lazzyy\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\lazzyy\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\SkyDriveShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-479257388-3634607433-1617756106-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\17.0.4035.0328\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points =========================

30-06-2015 00:04:48 Windows-Sicherung
30-06-2015 00:10:03 Windows Update
03-07-2015 15:50:03 Windows Update
06-07-2015 21:39:14 Windows-Sicherung
07-07-2015 22:46:31 Windows Update
09-07-2015 01:26:29 Revo Uninstaller's restore point - Mozilla Firefox 39.0 (x86 de)
09-07-2015 02:48:04 Revo Uninstaller's restore point - Mozilla Firefox 39.0 (x86 de)

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0D15FB05-DDE2-4F40-A56F-CB41A45A35F5} - System32\Tasks\GU5SkipUAC => C:\Program Files (x86)\Glary Utilities 5\Integrator.exe [2014-06-03] (Glarysoft Ltd)
Task: {13EB2625-D6C1-4FBD-A551-122F008041FF} - System32\Tasks\HP AR Program Upload - f1968a237e824f1aac56549d8184b39ff8a9e9ea862440da8e76c91d923d9a8e => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {239DC78C-78E0-4712-B88F-9613AD91E785} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-09] (Adobe Systems Incorporated)
Task: {2B590E4A-912A-499F-B212-7BE5D8885942} - System32\Tasks\Opera scheduled Autoupdate 1401804726 => C:\Program Files (x86)\Opera\launcher.exe [2015-06-19] (Opera Software)
Task: {331EE7CF-85AC-4461-B67A-3641F9816F74} - System32\Tasks\{CAFA87E7-5B0E-4D6A-93D9-41C8A04C3F8E} => pcalua.exe -a C:\Users\lxxxxx\Downloads\wlsetup-web.exe -d C:\Users\lxxxxx\Downloads
Task: {48A209B5-AA2D-45CE-ACE7-B1CA2F979172} - System32\Tasks\HPCustParticipation HP Officejet 6700 => C:\Program Files\HP\HP Officejet 6700\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {4AF9CFD7-9A0E-4A20-AFF7-77595F97912A} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-03] (Google Inc.)
Task: {4BF0598C-36F1-4E04-97FB-966EA800733B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-06-03] (Google Inc.)
Task: {6D92F43E-CA02-48D1-806B-F9645C42C55F} - System32\Tasks\Uninstaller_SkipUac_lazzyy => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2015-07-09] (IObit)
Task: {77C78D64-44CA-4F07-B984-C7E75DE09E47} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated)
Task: {85E0CFE5-ED27-461E-B0B5-64C639234CD0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-05-20] (Piriform Ltd)
Task: {8C463591-B8BC-4012-8BB9-D82CE68E9612} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2014-06-03] (Glarysoft Ltd)
Task: {A3CE22B5-4185-40F0-A185-93B07931397D} - System32\Tasks\HP AR Program Upload - 8dc37cfbbe5c4f059cab48437ef87ad787a7744ea3d2478eb8cf20e9dd897e9f => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {B7087859-6698-4B73-B54D-4A59475B6BD1} - System32\Tasks\HP AR Program Upload - 7ff5e0a1a5934275be8c8d37eb8932441c42c281b9c74d9e89ef987ddd215ffc => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {CEF591EC-E41D-4FED-9E30-980843C425C5} - System32\Tasks\HP AR Program Upload - ffe403e0ab8f4198b9fa1da2f8f6350582569d660e024e99a86b80da37b9acf6 => C:\Program Files\HP\HP Officejet 6700\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GlaryInitialize 5.job => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2008-10-24 16:35 - 2008-10-24 16:35 - 00128296 _____ () C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
2013-11-01 11:46 - 2013-11-01 11:46 - 00214528 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2013-07-26 05:59 - 2013-07-26 05:59 - 00814592 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Device.dll
2013-07-26 05:59 - 2013-07-26 05:59 - 03650560 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Platform.dll
2014-06-04 00:56 - 2014-12-04 11:38 - 00042496 _____ () C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
2013-11-01 11:46 - 2013-11-01 11:46 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll
2014-08-04 00:39 - 2011-01-13 11:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll
2015-05-20 13:47 - 2015-05-20 13:47 - 03350640 _____ () C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll
2015-05-20 13:47 - 2015-05-20 13:47 - 00158832 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAP32V60.dll
2015-05-20 13:47 - 2015-05-20 13:47 - 00023152 _____ () C:\Program Files (x86)\Mozilla Thunderbird\NSLDAPPR32V60.dll
2015-06-25 13:50 - 2015-06-25 13:49 - 01649272 _____ () C:\Program Files (x86)\Opera\30.0.1835.88\libglesv2.dll
2015-06-25 13:50 - 2015-06-25 13:49 - 00081016 _____ () C:\Program Files (x86)\Opera\30.0.1835.88\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-479257388-3634607433-1617756106-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{09FF651C-67A9-468E-81C2-5DF8D6DD4CE1}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\FaxApplications.exe
FirewallRules: [{9B4E79DA-DCA3-4E0C-9F2B-E8CA186B24B6}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\DigitalWizards.exe
FirewallRules: [{A369D5B9-1D02-4E17-AD34-533ECA8486C6}] => (Allow) C:\Program Files\HP\HP Officejet 6700\bin\SendAFax.exe
FirewallRules: [{3E47F44E-8609-44D6-ABC4-2658288C431C}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\DeviceSetup.exe
FirewallRules: [{9E111A7C-E2F7-41B4-B504-A4ADD4751613}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
FirewallRules: [{DB00A7DB-A842-4B42-AC53-523114D1F317}] => (Allow) C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{CA4D1AC4-837F-41C8-A941-34719BF26A6D}] => (Allow) C:\Users\lxxxxx\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{6CCD0811-4563-425C-BFD8-9A2ADB1A55B2}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{129ABF9A-C4E6-4E5D-B4D0-FBAE990C51BB}] => (Allow) LPort=2869
FirewallRules: [{8BF8FCCD-5B06-4343-83E0-2244EB3B46AD}] => (Allow) LPort=1900
FirewallRules: [{325A9DF6-4BE7-4928-BAD7-C176956D5194}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{52659777-06C9-4773-BF70-869C9CA9AB2B}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
FirewallRules: [{186659B8-57D8-4D9D-8C8D-7644F6BE7BEE}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
FirewallRules: [{DEE1F2D5-24E5-4FAC-97C9-29B251ABE36B}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\app\StarMoney.exe
FirewallRules: [{AC3840B2-B76A-44A9-BCB0-73F3A297A21B}] => (Allow) C:\Program Files (x86)\StarMoney 9.0\app\StarMoney.exe
FirewallRules: [{636AB5DB-43B7-4859-B01B-8CAE4CE1DE4C}] => (Allow) LPort=80
FirewallRules: [{F9FA9DAF-623E-4C3B-BE53-41F7F6FCB867}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{FB96EF5E-AE06-4512-8BE6-EDAEF64EE243}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{35C873E8-79BE-4A5A-9448-E0C87AC127B0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Faulty Device Manager Devices =============

Name: Microsoft-Teredo-Tunneling-Adapter
Description: Microsoft-Teredo-Tunneling-Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/09/2015 10:46:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2015 04:13:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2015 02:47:42 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2015 00:17:30 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2015 02:05:07 PM) (Source: Adobe Reader) (EventID: 16) (User: )
Description: 

Error: (07/08/2015 01:36:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/07/2015 10:34:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/07/2015 02:10:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/06/2015 09:30:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/06/2015 04:09:16 PM) (Source: Adobe Reader) (EventID: 16) (User: )
Description: 


System errors:
=============
Error: (07/09/2015 10:44:39 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "SuperEasy 1-Click Backup" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%3

Error: (07/09/2015 04:16:34 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Der Dienst "Windows Update" wurde nicht richtig gestartet.

Error: (07/09/2015 04:11:53 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "SuperEasy 1-Click Backup" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (07/09/2015 04:11:32 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Das System wurde zuvor am ‎09.‎07.‎2015 um 04:04:47 unerwartet heruntergefahren.

Error: (07/09/2015 02:46:45 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "SuperEasy 1-Click Backup" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%2

Error: (07/09/2015 02:45:08 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1069

Error: (07/09/2015 02:45:08 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Der Dienst "WSearch" konnte sich nicht als "NT AUTHORITY\SYSTEM" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden: 
%%50

Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).

Error: (07/09/2015 02:44:48 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 2 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (07/09/2015 02:44:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.

Error: (07/09/2015 02:44:38 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts.


Microsoft Office:
=========================
Error: (07/09/2015 10:46:17 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2015 04:13:16 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2015 02:47:42 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/09/2015 00:17:30 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2015 02:05:07 PM) (Source: Adobe Reader) (EventID: 16) (User: )
Description: 

Error: (07/08/2015 01:36:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/07/2015 10:34:08 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/07/2015 02:10:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/06/2015 09:30:14 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/06/2015 04:09:16 PM) (Source: Adobe Reader) (EventID: 16) (User: )
Description: 


CodeIntegrity Errors:
===================================
  Date: 2015-02-12 03:40:11.947
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-02-12 03:40:11.897
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-02-12 03:40:11.896
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-02-12 03:40:11.895
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.

  Date: 2015-02-12 03:40:11.867
  Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX64\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.


==================== Memory info =========================== 

Processor: AMD A8-6600K APU with Radeon(tm) HD Graphics 
Percentage of memory in use: 34%
Total physical RAM: 7364.8 MB
Available physical RAM: 4799.22 MB
Total Virtual: 14727.82 MB
Available Virtual: 11574.88 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.17 GB) (Free:745.49 GB) NTFS
Drive g: () (Removable) (Total:1.89 GB) (Free:0.99 GB) FAT
Drive j: () (Fixed) (Total:931.51 GB) (Free:541.55 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 18565D10)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.2 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 00DA6471)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 5 (Size: 1.9 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.

==================== End of log ============================
         
--- --- ---

--- --- ---
__________________

Geändert von michelle80 (09.07.2015 um 11:37 Uhr)

Alt 09.07.2015, 14:19   #4
schrauber
/// the machine
/// TB-Ausbilder
 

Malware bei Facebook - Standard

Malware bei Facebook



Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.


Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.


und ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2015, 17:08   #5
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo Schrauber,

Mbam habe ich schonmal fertig :-)




Malwarebytes Anti-Malware
www.malwarebytes.org

Suchlaufdatum: 09.07.2015
Suchlaufzeit: 15:56
Protokolldatei: mbam.txt
Administrator: Ja

Version: 2.1.8.1057
Malware-Datenbank: v2015.07.09.03
Rootkit-Datenbank: v2015.07.09.01
Lizenz: Premium-Version
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert

Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: lxxxxx

Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 400698
Abgelaufene Zeit: 16 Min., 42 Sek.

Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert

Prozesse: 0
(keine bösartigen Elemente erkannt)

Module: 0
(keine bösartigen Elemente erkannt)

Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)

Registrierungswerte: 0
(keine bösartigen Elemente erkannt)

Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)

Ordner: 0
(keine bösartigen Elemente erkannt)

Dateien: 0
(keine bösartigen Elemente erkannt)

Physische Sektoren: 0
(keine bösartigen Elemente erkannt)


(end)

AdwCleaner ist fertig

Ich habe diese Datei in Verdacht!

[ Datei : C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\prefs.js ]







AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v3.212 - Bericht erstellt am 13/06/2014 um 15:08:11
# Aktualisiert 05/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : lxxxxx - Lxxxxx-PC
# Gestartet von : C:\Users\lxxxxx\Downloads\adwcleaner_3.212(1).exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.17126


-\\ Mozilla Firefox v29.0.1 (de)

[ Datei : C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\prefs.js ]


-\\ Google Chrome v35.0.1916.153

[ Datei : C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [6912 octets] - [12/06/2014 05:32:36]
AdwCleaner[R1].txt - [1067 octets] - [13/06/2014 14:55:33]
AdwCleaner[S0].txt - [6360 octets] - [12/06/2014 05:41:51]
AdwCleaner[S1].txt - [990 octets] - [13/06/2014 15:08:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1049 octets] ##########
         
--- --- ---
AdwCleaner Logfile:
Code:
ATTFilter
# AdwCleaner v4.207 - Bericht erstellt 09/07/2015 um 16:21:27
# Aktualisiert 21/06/2015 von Xplode
# Datenbank : 2015-07-05.2 [Server]
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64)
# Benutzername : lxxxxx - Lxxxxx-PC
# Gestarted von : C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe
# Option : Löschen

***** [ Dienste ] *****


***** [ Dateien / Ordner ] *****


***** [ Geplante Tasks ] *****


***** [ Verknüpfungen ] *****


***** [ Registrierungsdatenbank ] *****


***** [ Internetbrowser ] *****

-\\ Internet Explorer v11.0.9600.17840


-\\ Mozilla Firefox v39.0 (x86 de)


-\\ Google Chrome v43.0.2357.132



-\\ Opera v30.0.1835.88


*************************

AdwCleaner[R0].txt - [9130 Bytes] - [12/06/2014 05:32:36]
AdwCleaner[R1].txt - [3285 Bytes] - [13/06/2014 14:55:33]
AdwCleaner[R2].txt - [2277 Bytes] - [09/07/2015 02:43:29]
AdwCleaner[R3].txt - [1158 Bytes] - [09/07/2015 02:57:25]
AdwCleaner[R4].txt - [1217 Bytes] - [09/07/2015 03:02:27]
AdwCleaner[R5].txt - [1281 Bytes] - [09/07/2015 16:20:03]
AdwCleaner[S0].txt - [8591 Bytes] - [12/06/2014 05:41:51]
AdwCleaner[S1].txt - [2271 Bytes] - [13/06/2014 15:08:11]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2330  Bytes] ##########
         
--- --- ---

JRT ist auch fertigJRT Logfile:
Code:
ATTFilter
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.3.8 (07.09.2015:1)
OS: Windows 7 Home Premium x64
Ran by lxxxxx on 09.07.2015 at 16:31:21,40
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Tasks

Successfully deleted: [Task] C:\Windows\system32\tasks\Uninstaller_SkipUac_lxxxxx



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update webporpoise
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Util webporpoise



~~~ Files

Successfully deleted: [File] C:\Users\lxxxxx\appdata\local\998087a8e589f390f0b710fed8b8c1bf
Successfully deleted: [File] C:\users\public\desktop\drivereasy.lnk



~~~ Folders

Successfully deleted: [Folder] C:\ProgramData\microsoft\windows\start menu\programs\drivereasy
Successfully deleted: [Folder] C:\ProgramData\productdata
Successfully deleted: [Folder] C:\Users\lxxxxx\AppData\Roaming\productdata



~~~ FireFox

Emptied folder: C:\Users\lxxxxx\AppData\Roaming\mozilla\firefox\profiles\y9uvrwqa.default\minidumps [228 files]



~~~ Chrome


[C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Preferences] - default search provider reset

[C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:

[C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset

[C:\Users\lxxxxx\appdata\local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.07.2015 at 16:35:29,75
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         
--- --- ---
Ganz neues FRST
FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by lxxxxx (administrator) on Lxxxxx-PC on 09-07-2015 16:42:13
Running from C:\Users\lxxxxx\Downloads
Loaded Profiles: lxxxxx (Available Profiles: lxxxxx & _supereasy_1cbackup_)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\lxxxxxx\Downloads\FRST64 (1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC
HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL
HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] ()
Startup: C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
BootExecute: autocheck autochk *  

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( )
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF SearchPlugin: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\searchplugins\ecosia.xml [2015-05-29]
FF Extension: PAYBACK Toolbar - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\toolbar-ff@payback.de.xpi [2014-12-10]
FF Extension: Ecosia — The search engine that plants trees! - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2014-06-27]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-03]

Chrome: 
=======
CHR Profile: C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03]
CHR Extension: (Google Drive) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03]
CHR Extension: (YouTube) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03]
CHR Extension: (Google Search) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03]
CHR Extension: (Safe Money) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03]
CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03]
CHR Extension: (Virtual Keyboard) - C:\Users\lxxxxxAppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03]
CHR Extension: (Gmail) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03]
CHR Extension: (Anti-Banner) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed]
S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit)
S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
S2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 supereasy_1cbackup; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices)
R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm))
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-09 16:35 - 2015-07-09 16:38 - 00001946 _____ C:\Users\lxxxxx\Desktop\JRT.txt
2015-07-09 16:31 - 2015-07-09 16:31 - 00000207 _____ C:\Windows\tweaking.com-regbackup-Lxxxxx-PC-Windows-7-Home-Premium-(64-bit).dat
2015-07-09 16:31 - 2015-07-09 16:31 - 00000000 ____D C:\RegBackup
2015-07-09 16:29 - 2015-07-09 16:29 - 02953724 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT (1).exe
2015-07-09 16:16 - 2015-07-09 16:16 - 00001202 _____ C:\Users\lxxxxx\Desktop\mbam.txt
2015-07-09 16:04 - 2015-07-09 16:05 - 01981655 _____ C:\Users\lxxxxx\Downloads\u1501.zip
2015-07-09 16:04 - 2015-07-09 16:05 - 00000600 _____ C:\Users\lxxxxx\PUTTY.RND
2015-07-09 16:04 - 2015-07-09 16:04 - 01961239 _____ C:\Users\lxxxxx\Downloads\u__1304.zip
2015-07-09 15:52 - 2015-07-09 15:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lxxxxx\Downloads\mbam-setup-2.1.6.1022.exe
2015-07-09 11:41 - 2015-07-09 11:41 - 00033300 _____ C:\Users\lxxxxx\Desktop\Addition.txt
2015-07-09 11:00 - 2015-07-09 11:00 - 00062490 _____ C:\Users\lxxxxx\Desktop\FRST.txt
2015-07-09 10:49 - 2015-07-09 10:49 - 02112512 _____ (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe
2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT.exe
2015-07-09 04:22 - 2015-07-09 04:22 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe
2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit
2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxxx\Downloads\iobituninstaller4.3.0.122.exe
2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxxx\Downloads\rkill.exe
2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys
2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe
2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0.exe
2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxxx\Downloads\revosetup95 (1).exe
2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe
2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207.exe
2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure
2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxxx\Desktop\F-SecureOnlineScanner.exe
2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\F-Secure
2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxxx\Desktop\de-de.setup.exe
2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys
2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat
2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxxx\Desktop\IMG-20150701-WA0000.jpeg
2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxxx\Desktop\smil.xml
2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys
2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys
2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys
2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys
2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\mresreg
2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxxx\Desktop\diasetup.exe
2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2
2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI
2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg
2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\lxxxxx\Desktop\fotoworks_setup.exe
2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxxx\Desktop\bilder-27062015-0224.zip
2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxxx\Bilder von xxxxx xxxxx
2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys
2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys
2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys
2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys
2015-06-13 01:23 - 2015-06-13 01:23 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-12 15:41 - 2015-06-12 15:41 - 00017174 _____ C:\Users\lxxxxx\Documents\coolpad.odt
2015-06-11 14:42 - 2015-06-11 15:52 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1D534D16.sys
2015-06-10 15:53 - 2015-05-25 20:24 - 05569984 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-06-10 15:53 - 2015-05-25 20:23 - 00155584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2015-06-10 15:53 - 2015-05-25 20:23 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-06-10 15:53 - 2015-05-25 20:21 - 01728960 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 01255424 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 01162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00728576 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\sechost.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2015-06-10 15:53 - 2015-05-25 20:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00879104 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00404992 _____ (Microsoft Corporation) C:\Windows\system32\tracerpt.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\typeperf.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2015-06-10 15:53 - 2015-05-25 20:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2015-06-10 15:53 - 2015-05-25 20:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\diskperf.exe
2015-06-10 15:53 - 2015-05-25 20:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2015-06-10 15:53 - 2015-05-25 20:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:11 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 20:07 - 03989440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2015-06-10 15:53 - 2015-05-25 20:07 - 03934144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2015-06-10 15:53 - 2015-05-25 20:04 - 01310744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00635392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00551424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sechost.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2015-06-10 15:53 - 2015-05-25 20:01 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2015-06-10 15:53 - 2015-05-25 20:00 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tracerpt.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logman.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\typeperf.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00037888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\relog.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2015-06-10 15:53 - 2015-05-25 20:00 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\diskperf.exe
2015-06-10 15:53 - 2015-05-25 19:59 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2015-06-10 15:53 - 2015-05-25 19:59 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2015-06-10 15:53 - 2015-05-25 19:59 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2015-06-10 15:53 - 2015-05-25 19:59 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2015-06-10 15:53 - 2015-05-25 19:57 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2015-06-10 15:53 - 2015-05-25 19:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 19:00 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-06-10 15:53 - 2015-05-25 18:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2015-06-10 15:53 - 2015-05-25 18:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2015-06-10 15:53 - 2015-05-25 18:48 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 18:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 18:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2015-06-10 15:53 - 2015-05-25 18:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00700416 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00423424 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2015-06-10 15:53 - 2015-05-22 20:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-06-10 15:53 - 2015-05-22 20:13 - 01119232 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-06-10 15:53 - 2015-05-21 15:19 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2015-06-10 15:53 - 2015-04-29 20:22 - 14635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-06-10 15:53 - 2015-04-29 20:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2015-06-10 15:53 - 2015-04-29 20:21 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2015-06-10 15:53 - 2015-04-29 20:19 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2015-06-10 15:53 - 2015-04-29 20:07 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-06-10 15:53 - 2015-04-29 20:07 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2015-06-10 15:53 - 2015-04-29 20:07 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2015-06-10 15:53 - 2015-04-29 20:05 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2015-06-10 15:52 - 2015-05-25 19:08 - 03206144 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-06-10 15:52 - 2015-04-24 20:17 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2015-06-10 15:52 - 2015-04-24 19:56 - 00530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll
2015-06-10 15:52 - 2015-04-11 05:19 - 00069888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stream.sys
2015-06-10 15:51 - 2015-06-01 21:16 - 00389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-06-10 15:51 - 2015-06-01 20:07 - 00342736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-06-10 15:51 - 2015-05-27 16:35 - 24917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-06-10 15:51 - 2015-05-27 16:08 - 19607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-06-10 15:51 - 2015-05-23 05:28 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-06-10 15:51 - 2015-05-23 05:15 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-06-10 15:51 - 2015-05-23 05:15 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2015-06-10 15:51 - 2015-05-23 05:15 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2015-06-10 15:51 - 2015-05-23 05:14 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-06-10 15:51 - 2015-05-23 05:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2015-06-10 15:51 - 2015-05-23 05:10 - 02278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-06-10 15:51 - 2015-05-23 05:09 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-06-10 15:51 - 2015-05-23 05:08 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2015-06-10 15:51 - 2015-05-23 05:06 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-06-10 15:51 - 2015-05-23 05:05 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-06-10 15:51 - 2015-05-23 05:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-06-10 15:51 - 2015-05-23 05:04 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2015-06-10 15:51 - 2015-05-23 04:57 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-06-10 15:51 - 2015-05-23 04:52 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2015-06-10 15:51 - 2015-05-23 04:49 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2015-06-10 15:51 - 2015-05-23 04:48 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-06-10 15:51 - 2015-05-23 04:47 - 04305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-06-10 15:51 - 2015-05-23 04:47 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-06-10 15:51 - 2015-05-23 04:38 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-06-10 15:51 - 2015-05-23 04:37 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-06-10 15:51 - 2015-05-23 04:37 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2015-06-10 15:51 - 2015-05-23 04:28 - 12829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-06-10 15:51 - 2015-05-23 04:20 - 01950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-06-10 15:51 - 2015-05-23 04:16 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-06-10 15:51 - 2015-05-23 04:14 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-06-10 15:51 - 2015-05-22 21:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-06-10 15:51 - 2015-05-22 21:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-06-10 15:51 - 2015-05-22 21:01 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-06-10 15:51 - 2015-05-22 21:00 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-06-10 15:51 - 2015-05-22 21:00 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-06-10 15:51 - 2015-05-22 21:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-06-10 15:51 - 2015-05-22 21:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-06-10 15:51 - 2015-05-22 20:59 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-06-10 15:51 - 2015-05-22 20:53 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-06-10 15:51 - 2015-05-22 20:52 - 06026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-06-10 15:51 - 2015-05-22 20:52 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-06-10 15:51 - 2015-05-22 20:48 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-06-10 15:51 - 2015-05-22 20:47 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-06-10 15:51 - 2015-05-22 20:47 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-06-10 15:51 - 2015-05-22 20:47 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-06-10 15:51 - 2015-05-22 20:47 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-06-10 15:51 - 2015-05-22 20:40 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-06-10 15:51 - 2015-05-22 20:36 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-06-10 15:51 - 2015-05-22 20:29 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-06-10 15:51 - 2015-05-22 20:25 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-06-10 15:51 - 2015-05-22 20:24 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-06-10 15:51 - 2015-05-22 20:21 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-06-10 15:51 - 2015-05-22 20:07 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-06-10 15:51 - 2015-05-22 20:06 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-06-10 15:51 - 2015-05-22 20:05 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-06-10 15:51 - 2015-05-22 20:05 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-06-10 15:51 - 2015-05-22 19:57 - 14404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-06-10 15:51 - 2015-05-22 19:50 - 02426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-06-10 15:51 - 2015-05-22 19:38 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-06-10 15:51 - 2015-05-22 19:26 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-06-10 00:39 - 2015-06-10 00:39 - 00013412 _____ C:\Users\lxxxxx\Documents\mxxxxxxxxx.odt

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-09 16:42 - 2014-06-12 09:00 - 00018964 _____ C:\Users\lxxxxx\Downloads\FRST.txt
2015-07-09 16:42 - 2014-06-12 08:59 - 00000000 ____D C:\FRST
2015-07-09 16:30 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-09 16:30 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-09 16:28 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat
2015-07-09 16:28 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat
2015-07-09 16:28 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-09 16:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-09 16:25 - 2014-06-02 10:56 - 01922482 _____ C:\Windows\WindowsUpdate.log
2015-07-09 16:23 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job
2015-07-09 16:23 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-09 16:22 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-09 16:22 - 2014-06-05 15:51 - 00056918 _____ C:\Windows\setupact.log
2015-07-09 16:22 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini
2015-07-09 16:22 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-09 16:22 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-09 16:21 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner
2015-07-09 16:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-09 16:04 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxxx
2015-07-09 15:55 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-09 11:41 - 2014-06-12 09:01 - 00033300 _____ C:\Users\lxxxxx\Downloads\Addition.txt
2015-07-09 10:44 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia
2015-07-09 04:11 - 2014-06-06 03:18 - 00019030 _____ C:\Windows\PFRO.log
2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_
2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-09 01:25 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxxx\Desktop\Revo Uninstaller.lnk
2015-07-09 01:25 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxx
2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxx
2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxxx\Bilder vonxxxx
2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxxx\Bilderxxxxxx
2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontxxxxxx Mxxxx
2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kontxxxxxx Mxxxx
2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilder mit xxxx
2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neue xxxx xxxxx
2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\VirtualStore
2015-06-26 01:47 - 2014-06-06 03:27 - 00000000 ____D C:\A1-Faktura
2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726
2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera
2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxxx\Fxxxxxx
2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxx\Documents\Dxxxxxx.odt
2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bildxxxxxxxx
2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\Adobe
2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\Adobe
2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe
2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle
2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxx\Desktop\jxpiinstall.exe
2015-06-13 01:23 - 2014-06-03 15:47 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-10 22:29 - 2009-07-14 06:45 - 00296104 _____ C:\Windows\system32\FNTCACHE.DAT
2015-06-10 22:27 - 2014-12-10 06:09 - 00000000 ____D C:\Windows\system32\appraiser
2015-06-10 22:27 - 2014-06-05 03:10 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-06-10 22:27 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-06-10 16:06 - 2014-03-13 13:01 - 00000000 ____D C:\Windows\system32\MRT
2015-06-10 16:02 - 2014-03-13 13:01 - 140135120 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-06-10 15:30 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Files in the root of some directories =======

2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\lxxxxx\cc_20140606_180858.reg


Some files in TEMP:
====================
C:\Users\lxxxxx\AppData\Local\Temp\Quarantine.exe
C:\Users\lxxxxx\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-04 15:15

==================== End of log ============================
         
--- --- ---


Alt 10.07.2015, 09:07   #6
schrauber
/// the machine
/// TB-Ausbilder
 

Malware bei Facebook - Standard

Malware bei Facebook




ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset


Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
__________________
--> Malware bei Facebook

Alt 11.07.2015, 02:34   #7
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo Schrauber,

Eset hat so einiges gefunden


ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 02:51:42
# local_time=2015-07-10 04:51:42 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24740
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 02:58:04
# local_time=2015-07-10 04:58:04 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# engine=24740
# end=stopped
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-07-10 03:01:25
# local_time=2015-07-10 05:01:25 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777213 100 100 2819 68018507 0 0
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 4225759 59524479 0 0
# scanned=5036
# found=2
# cleaned=0
# scan_time=200
sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 03:03:49
# local_time=2015-07-10 05:03:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
esets_scanner_update returned -1 esets_gle=53251
Update Finalize
Updated modules version: 24740
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 03:04:32
# local_time=2015-07-10 05:04:32 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# engine=24740
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-07-10 03:10:24
# local_time=2015-07-10 05:10:24 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777213 100 100 3358 68019046 0 0
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 4226298 59525018 0 0
# scanned=17924
# found=2
# cleaned=0
# scan_time=351
sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir"
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 09:10:15
# local_time=2015-07-10 11:10:15 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24743
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 09:10:43
# local_time=2015-07-10 11:10:43 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=init
# utc_time=2015-07-10 10:25:31
# local_time=2015-07-11 12:25:31 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
Update Init
Update Download
Update Finalize
Updated modules version: 24746
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# end=updated
# utc_time=2015-07-10 10:25:58
# local_time=2015-07-11 12:25:58 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.1.7601 NT Service Pack 1
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=c5e21436d427434a9e80b871edbb09f2
# engine=24746
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2015-07-10 11:57:32
# local_time=2015-07-11 01:57:32 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1='Kaspersky Internet Security'
# compatibility_mode=1292 16777213 100 100 5673 68050674 0 0
# compatibility_mode_1='Microsoft Security Essentials'
# compatibility_mode=5895 16777213 100 100 4257926 59556646 0 0
# scanned=115552
# found=38
# cleaned=0
# scan_time=5493
sh=99F97AD369E8621AB4D17DF53E80E60FEE99C727 ft=1 fh=42567613b862d846 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxxx\AppData\Local\Temp\OCS\ocs_v71b.exe.vir"
sh=0ABC8ADF9D9E13D3D9BC26A52E01E51147905548 ft=1 fh=c48ce4d4114f6e4f vn="Win32/InstallMonetizer.AN evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\lxxxxx\AppData\Local\Temp\OCS\Downloads\fc14996dfa99adfc7baae624196888c5\785a6d7308790902373cc6e150959891\picpick _333inst.exe.vir"
sh=91738DC254FDC7041A3D934ED35F478BD7050C2A ft=1 fh=4f8f7046f2fcfbeb vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Desktop\TestDisk PhotoRec - CHIP-Installer.exe"
sh=80B86F2B7E604FC94778C110DD25641204D8209D ft=1 fh=88381e48320a06f7 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.2.0.0_0\mgHelperGCFB.dll"
sh=95ADC7925C2BB20FACE637E7031972F8E208FA33 ft=0 fh=0000000000000000 vn="Variante von Win32/SweetIM.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\External Extensions\{EEE6C373-6118-11DC-9C72-001320C79847}\SweetFB.crx"
sh=4F1EC034FA273DF15EBEF1E3FA66F819DB8A1943 ft=1 fh=752909aa377c6468 vn="Variante von Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\AppData\Roaming\OpenCandy\OpenCandy_D883580E954D4BFBA1C169803F66DE1D\registrybooster(9).exe"
sh=D60F6EBE31E049C5236DBCE204F82B3CC16AE311 ft=1 fh=f1eedba83c490651 vn="Variante von Win32/SweetIM.N evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Desktop\Programme\bundlesweetimsetup.exe"
sh=5B499F87EE8B3BF2E981BBA51F4C2732EC32599C ft=1 fh=d086c7dc76977fbd vn="Variante von Win32/Systweak evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Desktop\Programme\rcpsetup_softonic_sd.exe"
sh=457335C7D7CF3B76BDA5156BDFC9D2E55F5EB26E ft=1 fh=733834ea60493ef0 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Documents\Downloads\Integrated_CT2325506.exe"
sh=08E5233775142E9C220C190CAD3E27A549652193 ft=1 fh=1f207ee3eb72f580 vn="Variante von Win32/Systweak.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\adusetup_ashampoo.exe"
sh=D5D8C00EA49AA0455C4507AB8FAA0B7CFF3C6FA4 ft=1 fh=ba487aeb357dec5c vn="Variante von Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\asc-setup(2).exe"
sh=38D920413DA6977CEC22A54F59C537D61FB5E3A7 ft=1 fh=1552aabc3c379211 vn="Win32/ELEX.AH evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\asc-setup.exe"
sh=5010BDDBEDDF9DF52905ECE13A54AD1831760CFC ft=1 fh=ae0f36ec463e8583 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\ashampoo_photo_commander_8_8.4.0_8416.exe"
sh=31048732171730E332CF83C59A1E9C8F87FE9D9B ft=1 fh=69d728c96126b483 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\ashampoo_photo_optimizer_4_4.0.3_12123.exe"
sh=A286C0831A97F92D5B02D4B93E86530036A8699D ft=1 fh=541a6d15877510a0 vn="Variante von Win32/Toolbar.Conduit.B evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\ashampoo_winoptimizer_6_6.60_7259.exe"
sh=DFDAF3E7ED920730B123DA30F0B1F79837B28ABE ft=1 fh=14851b481a89f9f9 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxxvom alten Pc\lxxxxx\Downloads\FreeYouTubeDownload.exe"
sh=2898AC44F5B280E0A16E3ECEAED861EA6C1B122F ft=1 fh=90c5cb6befc06df7 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxx vom alten Pc\lxxxx\Downloads\FreeYouTubetoMP3Converter (1).exe"
sh=8547D1E5EACE099ECFE5EDBF6958FA077650894B ft=1 fh=61435738673b6524 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\FreeYouTubeToMP3Converter.exe"
sh=CA4465FED8127902C233876084962BE515219103 ft=1 fh=2aae4c570c2e1699 vn="Variante von Win32/ELEX.AG evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\gusetup(1).exe"
sh=22DD19DAE5F13FC01E8768E0AF7A6916D4B56AD8 ft=1 fh=d64b1c57ab7859c7 vn="Variante von Win32/Vittalia.H evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\installer_abc_amber_text_converter_5_07_Deutsch.exe"
sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch (1).exe"
sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch (2).exe"
sh=FD2E7E52315B75CF5A4CC9F58891A8392C0E3F36 ft=1 fh=d53cd0c16606807f vn="Win32/Toolbar.Babylon evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\installer_paint_shop_pro_x4_ultimate_14_0_0_332_Deutsch.exe"
sh=6341D91DE330954BB8D497FCF8D7D50043B7F38C ft=1 fh=5fb1c7e382475525 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Magix-Foto-Designer-Setup.exe"
sh=6381C969CBF840D71B6DC7073563BE074C44BD94 ft=1 fh=4baa470ede468fd4 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Paint NET - CHIP-Downloader(1).exe"
sh=0BD5AB3AC384C83014B59DF19100D07B209C1DD8 ft=1 fh=57cb94fce1dea516 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Paint NET - CHIP-Downloader.exe"
sh=05C4561F9C8843B923104E8D275364898C53B357 ft=1 fh=77b670143b46f13b vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxxx\Downloads\ranktracker643-jre-Downloader.exe"
sh=6BA3AD49D76DFB397D0FC14F0555A38353D2E662 ft=1 fh=0d40b11a59bb767f vn="Win32/RegistryBooster evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\registryboosterplc.exe"
sh=F78E1730B2A61817987EB987CE9C7629B05F1F13 ft=1 fh=250619b73124c19c vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter (1).exe"
sh=6DF41BE2115F17EF773045825B7AD168C46FD71E ft=1 fh=250619b710cddeb8 vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter.exe"
sh=9C1B9244769611DFAA18E0ADE669C1BC275848F8 ft=1 fh=250619b75fad7c7c vn="Win32/Toolbar.Widgi evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxxvom alten Pc\lxxxx\Downloads\Setup_FreeVideoConverter26.exe"
sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator(1).exe"
sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator(2).exe"
sh=47935A3CA85ADB764E1B2D1260FD7152B158369E ft=1 fh=ecaa409289e7c4b9 vn="Win32/SoftonicDownloader evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_bannershop-gif-animator.exe"
sh=BD5D8E1A532DC977499E96056023F9922A5213A1 ft=1 fh=ac2eabd5779085bf vn="Win32/SoftonicDownloader.A evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\SoftonicDownloader_fuer_koyote-free-video-converter.exe"
sh=CCD667FE196B0E1FAD991130AE214EF32169BE97 ft=1 fh=65ad072f5b9444d7 vn="Win32/SoftonicDownloader.D evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\SoftonicDownloader_fuer_photoscape.exe"
sh=846D95D63EDE9508EFC7CEEE1D145D7CE62988C3 ft=1 fh=ec23a4ae3310ce50 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Lxxxx\Lxxxx vom alten Pc\lxxxxx\Downloads\Software Downloads\FreeYouTubeToMP3Converter31132918 (1).exe"
sh=846D95D63EDE9508EFC7CEEE1D145D7CE62988C3 ft=1 fh=ec23a4ae3310ce50 vn="Win32/Toolbar.Conduit evtl. unerwünschte Anwendung" ac=I fn="C:\Users\lxxxx\Lxxxx vom alten Pc\lxxxx\Downloads\Software Downloads\FreeYouTubeToMP3Converter31132918.exe"



Security Check ist auch fertig

Results of screen317's Security Check version 1.004
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Microsoft Security Essentials
Kaspersky Internet Security
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Java 7 Update 75
Java 8 Update 45
Adobe Flash Player 18.0.0.203
Mozilla Firefox (39.0)
Mozilla Thunderbird (31.7.0)
Google Chrome (43.0.2357.130)
Google Chrome (43.0.2357.132)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
StarMoney 9.0 ouservice StarMoneyOnlineUpdate.exe
Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe
Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````

Ganz frisches FRST:



FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-07-2015
Ran by lxxxxx (administrator) on Lxxxx-PC on 11-07-2015 02:21:04
Running from C:\Users\lxxxxx\Downloads
Loaded Profiles: lxxxx (Available Profiles: lxxxx & _supereasy_1cbackup_)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(phonostar GmbH) C:\Program Files (x86)\phonostar-Player\phonostar.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC
HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL
HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] ()
Startup: C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
BootExecute: autocheck autochk *  

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default
FF DefaultSearchEngine: Ecosia
FF SelectedSearchEngine: Ecosia
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( )
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF SearchPlugin: C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\searchplugins\ecosia.xml [2015-05-29]
FF Extension: PAYBACK Toolbar - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\toolbar-ff@payback.de.xpi [2014-12-10]
FF Extension: Ecosia — The search engine that plants trees! - C:\Users\lxxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\y9uvrwqa.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2014-06-27]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-06-03]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-06-03]

Chrome: 
=======
CHR Profile: C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03]
CHR Extension: (Google Drive) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03]
CHR Extension: (YouTube) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03]
CHR Extension: (Google Search) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03]
CHR Extension: (Safe Money) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03]
CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03]
CHR Extension: (Virtual Keyboard) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03]
CHR Extension: (Gmail) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03]
CHR Extension: (Anti-Banner) - C:\Users\lxxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit)
S2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 supereasy_1cbackup; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices)
R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm))
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-11 02:16 - 2015-07-11 02:16 - 00852662 _____ C:\Users\lxxxxx\Downloads\SecurityCheck.exe
2015-07-11 02:14 - 2015-07-11 02:14 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_lxxxxx
2015-07-11 02:14 - 2015-07-11 02:14 - 00000000 ____D C:\ProgramData\ProductData
2015-07-10 17:02 - 2015-07-10 17:03 - 02870984 _____ (ESET) C:\Users\lxxxxx\Downloads\esetsmartinstaller_deu (1).exe
2015-07-10 16:48 - 2015-07-10 16:49 - 02870984 _____ (ESET) C:\Users\lxxxxx\Downloads\esetsmartinstaller_deu.exe
2015-07-09 19:43 - 2015-07-09 19:43 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\ProductData
2015-07-09 16:35 - 2015-07-09 16:38 - 00001946 _____ C:\Users\lxxxxx\Desktop\JRT.txt
2015-07-09 16:31 - 2015-07-09 16:31 - 00000207 _____ C:\Windows\tweaking.com-regbackup-Lxxxxx-PC-Windows-7-Home-Premium-(64-bit).dat
2015-07-09 16:31 - 2015-07-09 16:31 - 00000000 ____D C:\RegBackup
2015-07-09 16:29 - 2015-07-09 16:29 - 02953724 _____ (Malwarebytes Corporation) C:\Users\lxxxx\Downloads\JRT (1).exe
2015-07-09 16:16 - 2015-07-09 16:16 - 00001202 _____ C:\Users\lxxxx\Desktop\mbam.txt
2015-07-09 16:04 - 2015-07-09 16:05 - 01981655 _____ C:\Users\lxxxxx\Downloads\u1501.zip
2015-07-09 16:04 - 2015-07-09 16:05 - 00000600 _____ C:\Users\lxxxxx\PUTTY.RND
2015-07-09 16:04 - 2015-07-09 16:04 - 01961239 _____ C:\Users\lxxxxx\Downloads\u__1304.zip
2015-07-09 15:52 - 2015-07-09 15:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lxxxxx\Downloads\mbam-setup-2.1.6.1022.exe
2015-07-09 11:41 - 2015-07-09 11:41 - 00033300 _____ C:\Users\lxxxxx\Desktop\Addition.txt
2015-07-09 11:00 - 2015-07-09 11:00 - 00062490 _____ C:\Users\lxxxxx\Desktop\FRST.txt
2015-07-09 10:49 - 2015-07-09 10:49 - 02112512 _____ (Farbar) C:\Users\lxxxxx\Downloads\FRST64 (1).exe
2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxxx\Downloads\JRT.exe
2015-07-09 04:22 - 2015-07-09 04:22 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-09 04:22 - 2015-07-09 04:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe
2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit
2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxxx\Downloads\iobituninstaller4.3.0.122.exe
2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxxx\Downloads\rkill.exe
2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys
2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe
2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxxx\Downloads\Firefox Setup Stub 39.0.exe
2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxxx\Downloads\revosetup95 (1).exe
2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207 (1).exe
2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxxx\Downloads\adwcleaner_4.207.exe
2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure
2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxxx\Desktop\F-SecureOnlineScanner.exe
2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\F-Secure
2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxxx\Desktop\de-de.setup.exe
2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys
2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat
2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxxx\Desktop\IMG-20150701-WA0000.jpeg
2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxxx\Desktop\smil.xml
2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys
2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys
2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys
2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys
2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\mresreg
2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxxx\Desktop\diasetup.exe
2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2
2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI
2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg
2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\Lxxxxx\Desktop\fotoworks_setup.exe
2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxx\Desktop\bilder-27062015-0224.zip
2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxxx\Bilder von xxxxx
2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys
2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys
2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys
2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys
2015-06-13 01:23 - 2015-06-13 01:23 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
2015-06-12 15:41 - 2015-06-12 15:41 - 00017174 _____ C:\Users\lxxxxx\Documents\cxxxxx.odt
2015-06-11 14:42 - 2015-06-11 15:52 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1D534D16.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-11 02:21 - 2014-06-12 09:00 - 00020410 _____ C:\Users\lxxxx\Downloads\FRST.txt
2015-07-11 02:21 - 2014-06-12 08:59 - 00000000 ____D C:\FRST
2015-07-11 02:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-11 02:12 - 2014-06-02 10:56 - 02043516 _____ C:\Windows\WindowsUpdate.log
2015-07-11 01:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-11 01:12 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-11 00:51 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-11 00:31 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-11 00:31 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-11 00:29 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat
2015-07-11 00:29 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat
2015-07-11 00:29 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-11 00:23 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job
2015-07-11 00:22 - 2014-06-05 15:51 - 00057198 _____ C:\Windows\setupact.log
2015-07-11 00:22 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini
2015-07-11 00:22 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-11 00:22 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-09 16:21 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner
2015-07-09 16:04 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxxx
2015-07-09 15:55 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-09 11:41 - 2014-06-12 09:01 - 00033300 _____ C:\Users\lxxxxx\Downloads\Addition.txt
2015-07-09 10:44 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia
2015-07-09 04:11 - 2014-06-06 03:18 - 00019030 _____ C:\Windows\PFRO.log
2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_
2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-09 01:25 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxxx\Desktop\Revo Uninstaller.lnk
2015-07-09 01:25 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxx
2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxxx\Bilder vonxxxxxx
2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxx\Bilder vonxxxxxx
2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxx
2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxx
2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxx
2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilder xxxxxx
2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neue xxxxxxx
2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxx\AppData\Local\VirtualStore
2015-06-26 01:47 - 2014-06-06 03:27 - 00000000 ____D C:\A1-Faktura
2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726
2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera
2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxxx\Formular xxxxx
2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxx\Documents\xxxxxxxxxxxxxxxx.odt
2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bilderxxxxxxx
2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxxx\AppData\Roaming\Adobe
2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxxxx\AppData\Local\Adobe
2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe
2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle
2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxxx\Desktop\jxpiinstall.exe
2015-06-13 01:23 - 2014-06-03 15:47 - 00000000 ____D C:\Program Files (x86)\Google

==================== Files in the root of some directories =======

2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\lxxxxx\cc_20140606_180858.reg


Some files in TEMP:
====================
C:\Users\lxxxxx\AppData\Local\Temp\Quarantine.exe
C:\Users\lxxxxx\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-04 15:15

==================== End of log ============================
         
--- --- ---

Das Facebookproblem in Firefox besteht weiterhin, diesmal soll wieder ein anderer Scanner runtergeladen werden.

Eset hatte ja soviele Einträge gefunden, fast 40.
Müssen die denn nicht alle gelöscht werden? Ich habe die Checkbox zum Löschen nicht angeklickt gehabt.
Bisher war Eset der einziger Scanner, der diese Einträge gefunden hat.










Geändert von michelle80 (11.07.2015 um 02:41 Uhr)

Alt 11.07.2015, 16:01   #8
schrauber
/// the machine
/// TB-Ausbilder
 

Malware bei Facebook - Standard

Malware bei Facebook



Facebook scannt auf irgendeine Weise angeblich irgendwelche Daten und erkennt, dass der Rechner infiziert sein soll. Nach dem Zufallsprinzip wird dann irgendeiner der zig Scanner angeboten, die sich bei FB eingekauft haben.

Laut Logs ist alles gut. Die ESET Funde sind Downloads von Dir, meist auch in nem alten Ordner. Siehste ja im Log selbst. Ich würde den ganzen Ordner löschen.


Revo Uninstaller - Download - Filepony
damit Firefox deinstallieren, keine Daten behalten, Reste entfernen lassen, neu installieren.

Dann:
https://support.mozilla.org/de/kb/fi...einfach-loesen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 12.07.2015, 04:51   #9
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo Schrauber,

ich muss bei den alten PC Sachen erst noch schauen, was ich davon noch brauche, bevor ich das löschen kann.

Ich habe jetzt zwar schonmal den Firefox mit Revo deinstalliert und neuinstalliert und dann war ich bei der Support Seite von Mozilla für die Restaurierung.
Dann habe ich mich bei Facebook eingeloggt und hatte wieder die gleiche Anzeige, dass mein PC infiziert ist.

Alt 12.07.2015, 17:06   #10
schrauber
/// the machine
/// TB-Ausbilder
 

Malware bei Facebook - Standard

Malware bei Facebook



Hast Du die nur in Firefox? Teste mal Facebook mit dem Internet Explorer.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 13.07.2015, 05:12   #11
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo Schrauber,

ich habe das Facebookproblem nur in Firefox.

Opera, Google Chrome und Explorer sind nicht davon betroffen.

Ich habe jetzt mal folgendes gemacht:

den betroffenen Ordner mit den alten Daten auf eine externe Festplatte kopiert und dann vom Pc gelöscht und siehe da, das Facebookproblem hat sich erledigt, ich kann mich einloggen, ohne dass mir angezeigt wird, dass ich einen Virus habe. Das Problem war ja nur in Firefox, alle anderen Browser waren davon nicht betroffen.

Soll ich den Pc jetzt nochmal komplett durchscannen?

Eset hatte diese Dinge alle gefunden.

Alt 13.07.2015, 16:17   #12
schrauber
/// the machine
/// TB-Ausbilder
 

Malware bei Facebook - Standard

Malware bei Facebook



nur ein frisches FRST log bitte.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 14.07.2015, 00:42   #13
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo Schrauber,

ich habe ein aktuelles FRST gemacht:


FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-07-2015
Ran by lxxxx (administrator) on Lxxxx-PC on 14-07-2015 00:31:31
Running from C:\Users\lxxxx\Downloads
Loaded Profiles: lxxxx (Available Profiles: lxxxx & _supereasy_1cbackup_)
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
() C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.27.5\GoogleCrashHandler64.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera_crashreporter.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Opera Software) C:\Program Files (x86)\Opera\30.0.1835.88\opera.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [NUSB3MON] => C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe [97280 2012-04-11] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7203032 2013-10-22] (Realtek Semiconductor)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC
HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL
HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-11-01] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [37152 2014-06-03] (Glarysoft Ltd)
HKU\S-1-5-21-479257388-3634607433-1617756106-1001\...\Run: [phonostar-PlayerTimer] => C:\Program Files (x86)\phonostar-Player\phonostarTimer.exe [42496 2014-12-04] ()
Startup: C:\Users\lxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-06-03]
ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
BootExecute: autocheck autochk *  

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-479257388-3634607433-1617756106-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer64.dll [2015-07-09] (IObit)
BHO: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Content Blocker Plugin -> {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin -> {73455575-E40C-433C-9784-C78DC7761455} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll [2014-12-18] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Safe Money Plugin -> {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll [2014-06-03] (Kaspersky Lab ZAO)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-15] (Oracle Corporation)
BHO-x32: URL Advisor Plugin -> {E33CF602-D945-461A-83F0-819F76A199F8} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll [2014-06-03] (Kaspersky Lab ZAO)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{95A34309-0424-4A48-8ACC-627CE7D0719F}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\lxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\xq0dkekp.default-1436669174552
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_203.dll [2015-07-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_203.dll [2015-07-09] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1211151.dll [2014-04-15] (Adobe Systems, Inc.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-06-15] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @phonostar.de/phonostar-Player -> C:\Program Files (x86)\phonostar-Player\npphonostarDetectNP.dll [2015-02-26] ( )
FF Plugin HKU\S-1-5-21-479257388-3634607433-1617756106-1001: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\lxxxx\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)

Chrome: 
=======
CHR Profile: C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-03]
CHR Extension: (Google Drive) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-03]
CHR Extension: (YouTube) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-03]
CHR Extension: (Google Search) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-03]
CHR Extension: (Kaspersky URL Advisor) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-06-03]
CHR Extension: (Safe Money) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-06-03]
CHR Extension: (Dangerous Websites Blocker) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-06-03]
CHR Extension: (Virtual Keyboard) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-06-03]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Google Wallet) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-03]
CHR Extension: (Gmail) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-03]
CHR Extension: (Anti-Banner) - C:\Users\lxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-06-03]
CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-06-03] (Adobe Systems) [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-11-01] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2585376 2015-07-09] (IObit)
R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [697488 2014-07-04] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 supereasy_1cbackup; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-19] (Advanced Micro Devices)
R0 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20672 2014-06-03] (Glarysoft Ltd)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31648 2014-06-22] (REALiX(tm))
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [458336 2014-06-03] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [115296 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [625248 2014-06-03] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2014-06-03] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178272 2014-06-03] (Kaspersky Lab ZAO)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-07-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
S3 MTsensor; C:\Windows\system32\drivers\ASACPI.sys [8192 2005-03-29] ()
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
S0 BootDefragDriver; System32\drivers\BootDefragDriver.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-14 00:31 - 2015-07-14 00:31 - 00000000 ____D C:\Users\lxxxx\Downloads\FRST-OlderVersion
2015-07-13 06:12 - 2015-07-13 06:12 - 00000000 ____D C:\Program Files (x86)\ESET
2015-07-12 04:45 - 2015-07-12 04:46 - 00000000 ____D C:\Users\lxxxx\Desktop\Alte Firefox-Daten
2015-07-12 04:44 - 2015-07-12 04:44 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-07-12 04:44 - 2015-07-12 04:44 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-07-12 04:44 - 2015-07-12 04:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-12 04:42 - 2015-07-12 04:42 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0 (3).exe
2015-07-12 04:35 - 2015-07-12 04:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxx\Downloads\revosetup95 (3).exe
2015-07-12 04:35 - 2015-07-12 04:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxx\Downloads\revosetup95 (2).exe
2015-07-12 04:31 - 2015-07-12 04:31 - 00042536 _____ C:\Users\lxxxx\Desktop\ESET.txt
2015-07-12 00:34 - 2015-07-12 00:34 - 02870984 _____ (ESET) C:\Users\lxxxx\Downloads\esetsmartinstaller_deu (2).exe
2015-07-11 04:57 - 2015-07-11 04:57 - 00000000 ____D C:\Users\lxxxx\Documents\Updater
2015-07-11 02:16 - 2015-07-11 02:16 - 00852662 _____ C:\Users\lxxxx\Downloads\SecurityCheck.exe
2015-07-11 02:14 - 2015-07-12 04:31 - 00002908 _____ C:\Windows\System32\Tasks\Uninstaller_SkipUac_lxxxx
2015-07-11 02:14 - 2015-07-11 02:14 - 00000000 ____D C:\ProgramData\ProductData
2015-07-10 17:02 - 2015-07-10 17:03 - 02870984 _____ (ESET) C:\Users\Lxxxx\Downloads\esetsmartinstaller_deu (1).exe
2015-07-10 16:48 - 2015-07-10 16:49 - 02870984 _____ (ESET) C:\Users\lxxxx\Downloads\esetsmartinstaller_deu.exe
2015-07-09 19:43 - 2015-07-09 19:43 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\ProductData
2015-07-09 16:35 - 2015-07-09 16:38 - 00001946 _____ C:\Users\lxxx\Desktop\JRT.txt
2015-07-09 16:31 - 2015-07-09 16:31 - 00000207 _____ C:\Windows\tweaking.com-regbackup-Lxxxx-PC-Windows-7-Home-Premium-(64-bit).dat
2015-07-09 16:31 - 2015-07-09 16:31 - 00000000 ____D C:\RegBackup
2015-07-09 16:29 - 2015-07-09 16:29 - 02953724 _____ (Malwarebytes Corporation) C:\Users\lxxxx\Downloads\JRT (1).exe
2015-07-09 16:16 - 2015-07-09 16:16 - 00001202 _____ C:\Users\lxxxx\Desktop\mbam.txt
2015-07-09 16:04 - 2015-07-09 16:05 - 00000600 _____ C:\Users\lxxxx\PUTTY.RND
2015-07-09 15:52 - 2015-07-09 15:53 - 21546080 _____ (Malwarebytes Corporation ) C:\Users\lxxxx\Downloads\mbam-setup-2.1.6.1022.exe
2015-07-09 11:41 - 2015-07-09 11:41 - 00033300 _____ C:\Users\lxxxx\Desktop\Addition.txt
2015-07-09 11:00 - 2015-07-09 11:00 - 00062490 _____ C:\Users\lxxxx\Desktop\FRST.txt
2015-07-09 04:41 - 2015-07-09 04:41 - 02953707 _____ (Malwarebytes Corporation) C:\Users\lxxxx\Downloads\JRT.exe
2015-07-09 04:19 - 2015-07-09 04:19 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0 (2).exe
2015-07-09 03:22 - 2015-07-09 03:22 - 00001252 _____ C:\Users\lxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Uninstall Programs.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00001228 _____ C:\Users\Public\Desktop\IObit Uninstaller.lnk
2015-07-09 03:22 - 2015-07-09 03:22 - 00000000 ____D C:\ProgramData\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\IObit
2015-07-09 03:21 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\IObit
2015-07-09 03:19 - 2015-07-09 03:20 - 15889184 _____ (IObit) C:\Users\lxxxx\Downloads\iobituninstaller4.3.0.122.exe
2015-07-09 03:10 - 2015-07-09 03:10 - 01943800 _____ (Bleeping Computer, LLC) C:\Users\lxxxx\Downloads\rkill.exe
2015-07-09 02:55 - 2015-07-09 02:55 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\172C3BAE.sys
2015-07-09 02:50 - 2015-07-09 02:50 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0 (1).exe
2015-07-09 01:31 - 2015-07-09 01:31 - 00242928 _____ C:\Users\lxxxx\Downloads\Firefox Setup Stub 39.0.exe
2015-07-09 01:25 - 2015-07-09 01:25 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\lxxxx\Downloads\revosetup95 (1).exe
2015-07-09 01:23 - 2015-07-09 01:23 - 02244096 _____ C:\Users\lxxxx\Downloads\adwcleaner_4.207 (1).exe
2015-07-09 01:22 - 2015-07-09 01:22 - 02244096 _____ C:\Users\lxxxx\Downloads\adwcleaner_4.207.exe
2015-07-09 00:27 - 2015-07-09 00:39 - 00000000 ____D C:\ProgramData\F-Secure
2015-07-09 00:27 - 2015-07-09 00:27 - 00572456 _____ (F-Secure Corporation) C:\Users\lxxxx\Desktop\F-SecureOnlineScanner.exe
2015-07-09 00:27 - 2015-07-09 00:27 - 00000000 ____D C:\Users\lxxxx\AppData\Local\F-Secure
2015-07-08 16:07 - 2015-07-08 16:07 - 00416576 _____ (Kaspersky Lab) C:\Users\lxxxx\Desktop\de-de.setup.exe
2015-07-06 23:41 - 2015-07-06 23:41 - 00003584 _____ C:\Users\lxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-07-06 21:29 - 2015-07-06 21:29 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\55ED2575.sys
2015-07-03 15:32 - 2015-07-03 15:32 - 00003288 ____N C:\bootsqm.dat
2015-07-01 23:15 - 2015-07-01 23:15 - 00207349 _____ C:\Users\lxxxx\Desktop\IMG-20150701-WA0000.jpeg
2015-07-01 23:15 - 2015-07-01 23:15 - 00000256 _____ C:\Users\lxxxx\Desktop\smil.xml
2015-07-01 18:01 - 2015-07-01 23:09 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\10940049.sys
2015-07-01 18:01 - 2015-07-01 18:01 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6AAD0032.sys
2015-06-30 23:59 - 2015-07-01 14:12 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\767943A1.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\54A74377.sys
2015-06-30 23:59 - 2015-06-30 23:59 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C7C439E.sys
2015-06-30 00:42 - 2015-06-30 00:42 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\550E1672.sys
2015-06-27 21:55 - 2015-06-27 21:55 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\mresreg
2015-06-27 21:54 - 2015-06-27 21:56 - 39346840 _____ (IN MEDIA KG ) C:\Users\lxxxx\Desktop\diasetup.exe
2015-06-27 21:53 - 2015-07-09 03:22 - 00000000 ____D C:\Program Files (x86)\FotoWorksXL_2
2015-06-27 21:53 - 2015-06-27 21:53 - 00000000 ____D C:\Users\lxxxxx\AppData\Roaming\IN-MEDIAKG-TI
2015-06-27 21:52 - 2015-06-27 21:52 - 00000000 ____D C:\Program Files (x86)\mresreg
2015-06-27 21:50 - 2015-06-27 21:51 - 36964664 _____ (IN MEDIAKG TI ) C:\Users\lxxxx\Desktop\fotoworks_setup.exe
2015-06-27 02:25 - 2015-06-27 02:25 - 00942709 _____ C:\Users\lxxxx Desktop\bilder-27062015-0224.zip
2015-06-27 02:14 - 2015-06-27 02:26 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxxx
2015-06-27 00:41 - 2015-06-27 01:20 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\220D2BA0.sys
2015-06-23 00:12 - 2015-06-23 00:12 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\28755C5A.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\6C8C43E3.sys
2015-06-19 00:53 - 2015-06-19 00:53 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\428F43E0.sys
2015-06-15 16:36 - 2015-06-15 16:36 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-06-15 16:36 - 2015-06-15 16:36 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-06-14 00:47 - 2015-06-14 18:46 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\76213859.sys
2015-06-14 00:47 - 2015-06-14 00:47 - 00136408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\4C253856.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-07-14 00:31 - 2014-06-12 09:00 - 00018551 _____ C:\Users\lxxxx\Downloads\FRST.txt
2015-07-14 00:31 - 2014-06-12 08:59 - 00000000 ____D C:\FRST
2015-07-14 00:31 - 2014-06-12 08:58 - 02133504 _____ (Farbar) C:\Users\lxxxx\Downloads\FRST64.exe
2015-07-14 00:26 - 2014-06-03 17:10 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-14 00:20 - 2014-06-03 15:47 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-14 00:16 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-14 00:16 - 2009-07-14 06:45 - 00028720 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-14 00:14 - 2011-04-12 09:43 - 00699090 _____ C:\Windows\system32\perfh007.dat
2015-07-14 00:14 - 2011-04-12 09:43 - 00149230 _____ C:\Windows\system32\perfc007.dat
2015-07-14 00:14 - 2009-07-14 07:13 - 01619272 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-14 00:11 - 2014-06-02 10:56 - 01256473 _____ C:\Windows\WindowsUpdate.log
2015-07-14 00:09 - 2014-06-05 23:04 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-07-14 00:09 - 2014-06-03 17:43 - 00000336 _____ C:\Windows\Tasks\GlaryInitialize 5.job
2015-07-14 00:09 - 2014-06-03 15:33 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-14 00:07 - 2014-06-05 15:51 - 00057534 _____ C:\Windows\setupact.log
2015-07-14 00:07 - 2014-06-05 05:04 - 00000234 _____ C:\BackupLoader.ini
2015-07-14 00:07 - 2014-06-03 15:47 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-14 00:07 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-13 05:06 - 2014-07-11 15:45 - 00000000 ____D C:\Users\lxxxx\Lxxxx vom alten Pc
2015-07-13 02:40 - 2014-06-06 03:18 - 00020190 _____ C:\Windows\PFRO.log
2015-07-13 02:40 - 2014-06-03 15:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-12 05:06 - 2014-06-03 15:17 - 00000000 ____D C:\Users\lxxxx
2015-07-12 04:35 - 2014-06-03 17:38 - 00001264 _____ C:\Users\lxxxx\Desktop\Revo Uninstaller.lnk
2015-07-12 04:35 - 2014-06-03 17:38 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-12 04:05 - 2014-06-22 04:30 - 00000000 ____D C:\Program Files (x86)\SIW
2015-07-12 01:32 - 2014-06-06 03:27 - 00000000 ____D C:\A1-Faktura
2015-07-09 16:21 - 2014-06-12 05:32 - 00000000 ____D C:\AdwCleaner
2015-07-09 15:55 - 2014-06-05 23:04 - 00001102 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 
2015-07-09 15:55 - 2014-06-05 23:04 - 00000000 ____D C:\Program Files (x86)\ Malwarebytes Anti-Malware 
2015-07-09 11:41 - 2014-06-12 09:01 - 00033300 _____ C:\Users\lxxxx\Downloads\Addition.txt
2015-07-09 04:11 - 2015-02-10 02:06 - 00000000 ____D C:\Program Files (x86)\Secunia
2015-07-09 02:46 - 2014-06-06 18:02 - 00000000 ____D C:\Users\_supereasy_1cbackup_
2015-07-09 01:27 - 2014-06-03 17:10 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-07-09 01:26 - 2014-06-03 17:10 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-09 01:26 - 2014-06-03 17:10 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-08 15:48 - 2015-04-21 01:08 - 00000000 ____D C:\Users\lxxxx\Neue xxxxxxx
2015-07-08 15:21 - 2015-05-18 17:00 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxxxx
2015-07-07 23:22 - 2014-06-03 15:50 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-07 22:32 - 2014-06-10 03:33 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2015-07-06 23:59 - 2015-01-13 01:36 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieBrowserModeList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieUserList
2015-07-06 23:59 - 2014-06-05 21:38 - 00000000 __SHD C:\Users\lxxxxx\AppData\Local\EmieSiteList
2015-07-05 12:08 - 2010-11-21 05:27 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-07-03 03:41 - 2015-03-23 23:16 - 00000000 ____D C:\Users\lxxxx\Bilder xxxxxx
2015-07-02 16:28 - 2014-06-10 15:01 - 00000000 ____D C:\Users\lxxxx\Bilderxxxxxxx
2015-07-01 02:03 - 2014-09-09 01:22 - 00000000 ____D C:\Users\lxxxxxx\Downloads\Kxxxxxxxxxx
2015-07-01 02:02 - 2015-01-05 01:38 - 00000000 ____D C:\Users\lxxxxx\Downloads\Kxxxxxxxxxx
2015-06-30 04:10 - 2015-04-16 04:01 - 00000000 ____D C:\Users\lxxxxx\Bilderxxxxxx
2015-06-30 00:40 - 2015-05-18 01:42 - 00000000 ____D C:\Users\lxxxxx\Neuexxxxxxxxx
2015-06-27 21:55 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxxxx\AppData\Local\VirtualStore
2015-06-25 13:50 - 2014-06-03 16:42 - 00003854 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1401804726
2015-06-25 13:50 - 2014-06-03 16:12 - 00000000 ____D C:\Program Files (x86)\Opera
2015-06-24 02:32 - 2014-12-27 01:04 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-06-22 17:22 - 2014-06-14 02:36 - 00000000 ____D C:\Users\lxxxx\xxxxxxx
2015-06-22 02:21 - 2015-06-08 21:32 - 00012990 _____ C:\Users\lxxxxxx\Documents\xxxxxxxxx.odt
2015-06-18 12:19 - 2015-01-10 01:24 - 00000000 ____D C:\Users\lxxxxx\Bildxxxxxx
2015-06-18 08:41 - 2014-06-05 23:04 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-06-18 08:41 - 2014-06-05 23:04 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-06-17 11:34 - 2009-07-14 07:09 - 00000000 ____D C:\Windows\System32\Tasks\WPD
2015-06-15 23:08 - 2014-06-03 15:18 - 00000000 ____D C:\Users\lxxxx\AppData\Roaming\Adobe
2015-06-15 23:07 - 2014-08-21 05:14 - 00000000 ____D C:\Users\lxxxx\AppData\Local\Adobe
2015-06-15 16:36 - 2014-06-03 17:29 - 00000000 ____D C:\ProgramData\Adobe
2015-06-15 16:36 - 2014-06-03 17:28 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-06-15 16:33 - 2014-09-10 16:10 - 00000000 ____D C:\ProgramData\Oracle
2015-06-15 16:32 - 2015-02-10 02:13 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-15 16:29 - 2015-02-10 02:13 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-15 16:28 - 2015-04-02 03:26 - 00561248 _____ (Oracle Corporation) C:\Users\lxxxxx\Desktop\jxpiinstall.exe

==================== Files in the root of some directories =======

2015-07-06 23:41 - 2015-07-06 23:41 - 0003584 _____ () C:\Users\lxxxxx\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-06-03 17:05 - 2014-06-03 17:05 - 0000057 _____ () C:\ProgramData\Ament.ini
2014-06-02 11:08 - 2014-06-02 11:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\lxxxx\cc_20140606_180858.reg


Some files in TEMP:
====================
C:\Users\lxxxx\AppData\Local\Temp\Quarantine.exe
C:\Users\lxxxx\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-05-04 15:15

==================== End of log ============================
         
--- --- ---

Alt 14.07.2015, 11:21   #14
schrauber
/// the machine
/// TB-Ausbilder
 

Malware bei Facebook - Standard

Malware bei Facebook



Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:
ATTFilter
HKLM\...\Run: ["c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey] => MSC
HKLM\...\Run: ["C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s] => RTHDVCPL
HKLM\...\Run: ["C:\Program Files (x86)\ATI Technologies\AMDUSB3DeviceDetector\nusb3mon.exe"] => NUSB3MON
         

Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
  • Starte nun FRST erneut und klicke den Entfernen Button.
  • Das Tool erstellt eine Fixlog.txt.
  • Poste mir deren Inhalt.



Ansonsten sieht das gut aus
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 14.07.2015, 23:55   #15
michelle80
 
Malware bei Facebook - Standard

Malware bei Facebook



Hallo Schrauber,

die Fixlist habe ich erstellt.
Ich bekomme sie irgendwie nicht mit ins Frst.
Ich probiere es später nochmal. Die Fixlist ist im Ordner von Frst mit drin, aber Frst findet die Liste nicht.

Ich komme leider nicht weiter. Ich habe es nochmal probiert.
Ich habe die Fixlist nochmal abgespeichert, aber, das FRST findet sie einfach nicht.

Antwort

Themen zu Malware bei Facebook
anderen, browser, dateien, einloggen, exe, facebook, firefox, folge, folgende, geändert, google, infos, installiert, kaspersky, klick, klickt, malware, natürlich, neu, nichts, opera, passwort, pishing, problem, sauber, screenshot, secure



Ähnliche Themen: Malware bei Facebook


  1. Malware bei Facebook
    Log-Analyse und Auswertung - 09.07.2015 (6)
  2. Malware bei Facebook
    Log-Analyse und Auswertung - 09.07.2015 (1)
  3. 2x | Malware bei Facebook
    Mülltonne - 09.07.2015 (1)
  4. Malware bei Facebook
    Mülltonne - 09.07.2015 (1)
  5. Malware bei Facebook
    Plagegeister aller Art und deren Bekämpfung - 09.07.2015 (1)
  6. Facebook bereinigt zwei Millionen Computer von Malware
    Nachrichten - 24.06.2015 (0)
  7. Facebook: "Dein Computer muss gereinigt werden" (Virus/Malware?)
    Plagegeister aller Art und deren Bekämpfung - 12.11.2014 (11)
  8. Facebook-Malware, brwlrg113.z
    Plagegeister aller Art und deren Bekämpfung - 28.06.2014 (18)
  9. Malware über Facebook-PN?
    Smartphone, Tablet & Handy Security - 08.05.2014 (1)
  10. Facebook geperrt: Malware oder Trojaner verlangt Kreditkartenangaben zur Entsperrung des Accounts
    Plagegeister aller Art und deren Bekämpfung - 17.07.2013 (15)
  11. Facebook spielt verrückt; Malware ?
    Plagegeister aller Art und deren Bekämpfung - 04.10.2012 (1)
  12. Facebook Malware durch: http://www.offisense.co.il/lang/images.php?facebookimage=...6704
    Plagegeister aller Art und deren Bekämpfung - 29.11.2011 (3)
  13. Facebook-Trojaner: vinamost.net/images/facebook/get.php?image=IMG39348819.JPG
    Log-Analyse und Auswertung - 21.11.2011 (42)
  14. Facebook Malware, Antivieren-Programme finden nichts - Wie werde ich sie los?
    Log-Analyse und Auswertung - 21.11.2011 (16)
  15. Facebook Trojaner runtergeladen und Antivir findet andauernd neue Malware
    Plagegeister aller Art und deren Bekämpfung - 01.11.2011 (18)
  16. Zuerst Facebook-Virus-Neu aufgesetzt,cpu Auslastung 100%,bei Facebook-Games extrem lahm!
    Log-Analyse und Auswertung - 03.02.2011 (11)
  17. Skype - Facebook Virus foto :P h**p://facebook.twitterbizzer.com/member_profile.php
    Plagegeister aller Art und deren Bekämpfung - 27.08.2010 (6)

Zum Thema Malware bei Facebook - Hallo, ich habe das gleiche Problem wie der User Susi16. Ich gebe mal folgende Infos, vielleicht helfen sie weiter. Ich vermute, dass es sich um eine Facebook-Pishingseite handelt. Ich wollte - Malware bei Facebook...
Archiv
Du betrachtest: Malware bei Facebook auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.