pedro12345 | 07.07.2013 11:36 | so, ich habe alles ausgeführt.
Hier die Logs
AdwCleaner: Code:
# AdwCleaner v2.304 - Datei am 07/07/2013 um 12:21:11 erstellt
# Aktualisiert am 03/07/2013 von Xplode
# Betriebssystem : Windows 8 Pro (64 bits)
# Benutzer : Peter - PETER
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Peter\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default\foxydeal.sqlite
Datei Gelöscht : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default\searchplugins\Askcom.xml
Datei Gelöscht : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default\searchplugins\Conduit.xml
Ordner Gelöscht : C:\Program Files (x86)\Conduit
Ordner Gelöscht : C:\Users\Peter\AppData\Local\Conduit
Ordner Gelöscht : C:\Users\Peter\AppData\LocalLow\Conduit
Ordner Gelöscht : C:\Users\Peter\AppData\Roaming\OpenCandy
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3281675
Schlüssel Gelöscht : HKLM\Software\Conduit
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16599
Ersetzt : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&CUI=UN42722590742379417&ctid=CT3281675 --> hxxp://www.google.com
-\\ Mozilla Firefox v22.0 (de)
Datei : C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default\prefs.js
Gelöscht : user_pref("CT3281675_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\"[...]
Gelöscht : user_pref("Smartbar.ConduitHomepagesList", "hxxp://search.conduit.com/?ctid=CT3281675&CUI=UN34907856[...]
Gelöscht : user_pref("Smartbar.ConduitSearchEngineList", "entrusted Customized Web Search");
Gelöscht : user_pref("Smartbar.ConduitSearchUrlList", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3281675[...]
Gelöscht : user_pref("Smartbar.SearchFromAddressBarSavedUrl", "hxxp://www.google.com/search?sourceid=navclient&[...]
Gelöscht : user_pref("Smartbar.keywordURLSelectedCTID", "CT3281675");
Gelöscht : user_pref("browser.search.defaultengine", "Ask.com");
Gelöscht : user_pref("browser.search.defaultenginename", "Ask.com");
Gelöscht : user_pref("browser.search.defaultthis.engineName", "entrusted Customized Web Search");
Gelöscht : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3281675&CUI[...]
Gelöscht : user_pref("browser.search.order.1", "Ask.com");
Gelöscht : user_pref("smartBar.searchInNewTabOwner", "CT3281675");
*************************
JRT-Log: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Windows 8 Pro x64
Ran by Peter on 07.07.2013 at 12:24:47,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{E6CDAB7C-C20D-420A-AF96-51F34C5357E9}
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [File] "C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\if6ueips.default\extensions\jid0-Z0Vu9hJlqV0fhIAPqPfmUCNubYQ@jetpack.xpi"
Emptied folder: C:\Users\Peter\AppData\Roaming\mozilla\firefox\profiles\if6ueips.default\minidumps [58 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 07.07.2013 at 12:26:43,28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Fixlog: Code:
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-07-2013
Ran by Peter at 2013-07-07 12:28:59 Run:1
Running from C:\Users\Peter\Desktop
Boot Mode: Normal
==============================================
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => Value deleted successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Start Page => Value deleted successfully.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{E6CDAB7C-C20D-420A-AF96-51F34C5357E9} => Key not found.
HKCR\CLSID\{E6CDAB7C-C20D-420A-AF96-51F34C5357E9} => Key not found.
==== End of Fixlog ====
und noch ein neues scanlog von FRST
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013
Ran by Peter (administrator) on 07-07-2013 12:29:29
Running from C:\Users\Peter\Desktop
Windows 8 Pro (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Lenovo.) C:\WINDOWS\system32\ibmpmsvc.exe
(Authentec Inc.) C:\Program Files\ThinkVantage Fingerprint Software\upeksvr.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Softwareentwicklung Remus - ArchiCrypt) C:\WINDOWS\system32\ACRAMDiskHandlerService64R_D4.exe
(Broadcom Corporation.) C:\WINDOWS\system32\BtwRSupportService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\WINDOWS\system32\IProsetMonitor.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\VIRTSCRL\virtscrl.exe
(Lenovo Group Limited) C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPOSD.EXE
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\SHTCTKY.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Password Manager\password_manager.exe
(Lenovo Group Limited) C:\Program Files (x86)\Lenovo\Password Manager\password_manager.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\extapsup.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
() C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Dropbox, Inc.) C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(Intel Corporation) C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe
() C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
() C:\Program Files (x86)\Lenovo\LocationAware\lpdagent.exe
(Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s [13538376 2013-05-21] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4 [1308232 2013-05-20] (Realtek Semiconductor)
HKLM\...\Run: [TpShocks] TpShocks.exe [382248 2013-05-10] (Lenovo.)
HKLM\...\Run: [PasswordManager] C:\Program Files\Lenovo\Password Manager\password_manager.exe [1534888 2012-10-23] (Lenovo Group Limited)
HKLM\...\Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [LenovoOptMouseUpdate] C:\Program Files\Lenovo\HOTKEY\extapsup.exe [255480 2013-04-19] (Lenovo Group Limited)
HKLM\...\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe [x]
HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [2963184 2013-05-29] (Synaptics Incorporated)
HKLM\...\Run: [LnvMobHotspotClient] C:\Program Files\Lenovo\Lenovo Mobile Hotspot\MobileHotspotclient.exe [937976 2013-05-28] (Lenovo)
HKLM\...\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe [594936 2013-05-27] (Lenovo Corporation)
Winlogon\Notify\psfus: C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (Authentec Inc.)
HKCU\...\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun [3673728 2012-11-06] (DT Soft Ltd)
HKCU\...\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent [1635752 2013-05-04] (Valve Corporation)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKCU\...\Policies\system: [DisableTaskMgr] 0
MountPoints2: {2281668e-8466-11e2-beb1-3c970e590759} - "F:\setup.exe"
MountPoints2: {e6c31630-7cf3-11e2-bea8-3c970e590759} - "F:\setup.exe" -a
HKLM-x32\...\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [59392 2012-05-02] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-26] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin [1523360 2011-01-12] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-25] (Apple Inc.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -minimized [684024 2012-10-17] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
HKLM-x32\...\Run: [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" [132920 2013-05-30] (Intel Corporation)
HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-05-31] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PWMTRV] rundll32 C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL,PwrMgrBkGndMonitor [6618408 2013-06-04] (Lenovo Group Limited)
Lsa: [Notification Packages] scecli C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll
Startup: C:\ProgramData\Start Menu\Programs\Startup\Bluetooth.lnk
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Spyder3Utility.lnk
ShortcutTarget: Spyder3Utility.lnk -> C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe ()
Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Peter\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Peter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13-comm.msn.com
SearchScopes: HKCU - {7AFF137D-23DE-4688-ABB1-6B39E6F3E846} URL =
BHO: IePasswordManagerHelper Class - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files\Lenovo\Password Manager\tvtpwm_ie_com.dll (Lenovo Group Limited)
BHO-x32: Citavi Picker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: IePasswordManagerHelper Class - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Password Manager\tvtpwm_ie_com.dll (Lenovo Group Limited)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{AB94E8B7-CDFE-4189-8BD3-EB57E0CF062B}: [NameServer]193.189.244.225,193.189.244.206
FireFox:
========
FF ProfilePath: C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default
FF SelectedSearchEngine: Google
FF Homepage: hxxp://theawesomer.com/
FF Keyword.URL: hxxp://www.google.de/search?q=
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default\Extensions\ich@maltegoetz.de
FF Extension: groovesharkUnlocker - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default\Extensions\groovesharkUnlocker@overlord1337.xpi
FF Extension: No Name - C:\Users\Peter\AppData\Roaming\Mozilla\Firefox\Profiles\if6ueips.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKCU\...\Firefox\Extensions: [{F74D5734-46F5-4B16-96F0-1E7FBF41B750}] C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12
FF Extension: ThinkVantage Password Manager - C:\Program Files (x86)\Lenovo\Password Manager\PWM Firefox Extension\2.0b12
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-26] (Avira Operations GmbH & Co. KG)
R2 ArchiCrypt Ultimate RAM-Disk 4; C:\WINDOWS\system32\ACRAMDiskHandlerService64R_D4.exe [1580648 2013-04-30] (Softwareentwicklung Remus - ArchiCrypt)
S3 AVControlCenter; C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe [149496 2013-05-27] (Lenovo Corporation)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2228440 2013-04-24] (Broadcom Corporation.)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-05-30] (Intel Corporation)
R3 Lenovo Settings Service; C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe [2037240 2013-04-19] (Lenovo Group Limited)
R2 Lenovo System Agent Service; C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe [559504 2012-08-16] (LENOVO INCORPORATED.)
S3 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [683000 2013-05-27] (Lenovo Corporation)
R2 Lenovo.VIRTSCRLSVC; C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe [136288 2012-08-10] (Lenovo Group Limited)
R2 LnvHotSpotSvc; C:\Program Files\Lenovo\Lenovo Mobile Hotspot\LnvHotSpotSvc.exe [465912 2013-05-28] (Lenovo)
R2 LocationTaskManager; C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe [463352 2013-04-19] ()
S3 SUService; C:\Program Files (x86)\Lenovo\System Update\SUService.exe [22376 2013-04-11] ()
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R1 ACMoFlex64RD4; C:\WINDOWS\system32\drivers\ACMoFlex64RD4.sys [23656 2013-04-30] (Softwareentwicklung Remus - ArchiCrypt.de)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-03-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130016 2013-03-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-03-27] (Avira Operations GmbH & Co. KG)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [172760 2013-04-24] (Broadcom Corporation.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 BTWPANFL; C:\WINDOWS\system32\drivers\btwpanfl.sys [44912 2013-01-20] (Broadcom Corporation.)
S2 DgiVecp; C:\WINDOWS\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
S2 DgiVecp; C:\WINDOWS\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283200 2013-03-05] (DT Soft Ltd)
R3 e1cexpress; C:\Windows\system32\DRIVERS\e1c63x64.sys [468240 2013-02-21] (Intel Corporation)
R3 LnvHIDHW; C:\Windows\System32\drivers\LnvHIDHW.sys [27496 2012-07-30] (Lenovo)
R3 MbmLowExt; C:\Windows\System32\Drivers\MbmLowExt.sys [26112 2012-10-30] (Ericsson AB)
R3 MbmUsbSerial; C:\Windows\System32\Drivers\MbmUsbSerial.sys [72704 2012-07-03] (Ericsson AB)
R3 MkBusFilter; C:\Windows\System32\drivers\MbmDeviceFilter.sys [25600 2012-10-22] (Ericsson AB)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3311072 2013-02-21] (Intel Corporation)
R0 RAMDiskVE; C:\Windows\System32\Drivers\RAMDiskVE.sys [73040 2012-09-06] (Dataram, Inc.)
R3 RCUVCAVS; C:\Windows\system32\DRIVERS\RCUVCAVS.sys [149632 2012-08-02] (Ricoh co.,Ltd.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44784 2013-05-29] (Synaptics Incorporated)
R2 smihlp; C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys [13128 2011-05-30] (Authentec Inc.)
S3 Spyder3; C:\Windows\System32\drivers\Spyder3.sys [15360 2010-03-30] ()
R3 wmbclass; C:\Windows\System32\drivers\wmbclass.sys [230912 2013-04-09] (Microsoft Corporation)
S3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Windows (R) Win 7 DDK provider)
S3 BTCFilterService; \SystemRoot\system32\DRIVERS\motfilt.sys [x]
S3 intaud_WaveExtensible; \SystemRoot\system32\drivers\intelaud.sys [x]
S3 iwdbus; \SystemRoot\System32\drivers\iwdbus.sys [x]
S3 motccgp; \SystemRoot\System32\drivers\motccgp.sys [x]
S3 motccgpfl; \SystemRoot\System32\drivers\motccgpfl.sys [x]
S3 motmodem; \SystemRoot\system32\DRIVERS\motmodem.sys [x]
S3 MotoSwitchService; \SystemRoot\System32\drivers\motswch.sys [x]
S3 Motousbnet; \SystemRoot\system32\DRIVERS\Motousbnet.sys [x]
S3 motusbdevice; \SystemRoot\System32\drivers\motusbdevice.sys [x]
S3 NETwNs64; \SystemRoot\system32\DRIVERS\NETwNs64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-07-07 21:13 - 2013-07-07 21:13 - 00000000 ____D C:\FRST
2013-07-07 12:26 - 2013-07-07 12:26 - 00001057 ____A C:\Users\Peter\Desktop\JRT.txt
2013-07-07 12:24 - 2013-07-07 12:24 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Peter\Desktop\JRT.exe
2013-07-07 12:24 - 2013-07-07 12:24 - 00000000 ____D C:\Windows\ERUNT
2013-07-07 12:24 - 2013-07-07 12:24 - 00000000 ____D C:\JRT
2013-07-07 12:22 - 2013-07-07 12:22 - 00002934 ____A C:\Users\Peter\Desktop\AdwCleaner[S1].txt
2013-07-07 12:21 - 2013-07-07 12:21 - 00002934 ____A C:\AdwCleaner[S1].txt
2013-07-07 12:20 - 2013-07-07 12:20 - 00650027 ____A C:\Users\Peter\Desktop\adwcleaner.exe
2013-07-07 11:38 - 2013-07-07 10:50 - 01934636 ____A (Farbar) C:\Users\Peter\Desktop\FRST64.exe
2013-07-07 00:32 - 2013-07-07 00:32 - 00000000 ____D C:\Program Files (x86)\ThinkPad
2013-07-07 00:32 - 2013-06-04 07:40 - 00020736 ____A (Lenovo Group Limited) C:\Windows\System32\Drivers\TPPWR64V.SYS
2013-07-07 00:32 - 2013-05-27 12:57 - 16819192 ____A (Lenovo Corporation) C:\Windows\System32\LibDriverMft.dll
2013-07-07 00:32 - 2013-05-27 12:57 - 00076280 ____A (Lenovo Corporation) C:\Windows\System32\LibDriverMftStart.dll
2013-07-07 00:32 - 2013-05-27 12:52 - 00067064 ____A (Lenovo Corporation) C:\Windows\SysWOW64\LibDriverMftStart.dll
2013-07-07 00:32 - 2013-05-27 12:51 - 16820728 ____A (Lenovo Corporation) C:\Windows\SysWOW64\LibDriverMft.dll
2013-07-07 00:32 - 2013-05-24 19:05 - 02366320 ____A (Microsoft Corporation) C:\Windows\System32\WudfUpdate_01011.dll
2013-07-06 22:46 - 2013-07-06 22:46 - 00000000 ____D C:\Users\Peter\AppData\Roaming\Malwarebytes
2013-07-06 22:45 - 2013-07-06 22:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-04 09:08 - 2013-04-24 00:25 - 02232024 ____A (Broadcom Corporation.) C:\Windows\System32\BcmBtRSupport.dll
2013-07-04 09:08 - 2013-04-24 00:25 - 02228440 ____A (Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
2013-07-04 09:08 - 2013-04-24 00:25 - 00186584 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwaudio.sys
2013-07-04 09:08 - 2013-04-24 00:24 - 00228568 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwavdt.sys
2013-07-04 09:08 - 2013-04-24 00:24 - 00022744 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwrchid.sys
2013-07-04 09:08 - 2012-07-27 07:48 - 00040248 ____A (Broadcom Corporation.) C:\Windows\System32\Drivers\btwl2cap.sys
2013-07-04 09:07 - 2013-05-29 21:41 - 01048816 ____A (Synaptics Incorporated) C:\Windows\System32\SynCOM.dll
2013-07-04 09:07 - 2013-05-29 21:41 - 00540400 ____A (Synaptics Incorporated) C:\Windows\SysWOW64\SynCOM.dll
2013-07-04 09:07 - 2013-05-29 21:41 - 00460528 ____A (Synaptics Incorporated) C:\Windows\System32\Drivers\SynTP.sys
2013-07-04 09:07 - 2013-05-29 21:41 - 00229616 ____A (Synaptics Incorporated) C:\Windows\System32\SynTPAPI.dll
2013-07-04 09:07 - 2013-05-29 21:41 - 00178416 ____A (Synaptics Incorporated) C:\Windows\System32\SynTPCo14.dll
2013-07-04 09:07 - 2013-05-29 21:41 - 00114416 ____A (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCOM.dll
2013-07-04 09:07 - 2013-05-29 21:41 - 00044784 ____A (Synaptics Incorporated) C:\Windows\System32\Drivers\Smb_driver_Intel.sys
2013-07-03 20:58 - 2013-05-16 00:35 - 00144384 ____A (Microsoft Corporation) C:\Windows\System32\tssdisai.dll
2013-07-03 18:25 - 2013-07-03 18:25 - 00606352 ____A C:\Users\Peter\Desktop\Passbild-36aGenerator.exe
2013-07-03 18:25 - 2013-07-03 18:25 - 00000000 ____D C:\Users\Peter\AppData\Local\Passbild_Generator
2013-07-02 15:17 - 2013-07-02 15:17 - 00000000 ____D C:\Windows\msagent
2013-07-02 15:17 - 2000-05-22 16:58 - 00244416 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msflxgrd.ocx
2013-06-26 11:12 - 2013-06-26 11:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-25 19:23 - 2013-06-25 20:42 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-20 16:23 - 2013-06-20 16:23 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-20 16:23 - 2013-06-20 16:23 - 00000000 ____D C:\Program Files\iTunes
2013-06-20 16:23 - 2013-06-20 16:23 - 00000000 ____D C:\Program Files\iPod
2013-06-20 01:43 - 2013-06-20 01:43 - 00000000 ____D C:\Program Files (x86)\Dolby Home Theater v4
2013-06-20 01:43 - 2013-06-03 17:08 - 00000008 ____A C:\Windows\System32\Drivers\RTKHDAUD.DAT
2013-06-20 01:43 - 2013-05-21 21:50 - 03425608 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\RTKVHD64.sys
2013-06-20 01:43 - 2013-05-21 15:57 - 00142408 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RCoInstII64.dll
2013-06-20 01:43 - 2013-05-21 15:05 - 00576929 ____A C:\Windows\System32\Drivers\RTAIODAT.DAT
2013-06-20 01:43 - 2013-05-21 14:15 - 24962560 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RCoRes64.dat
2013-06-20 01:43 - 2013-05-20 16:16 - 01003592 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RtkApi64.dll
2013-06-20 01:43 - 2013-05-20 14:36 - 02794056 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RtPgEx64.dll
2013-06-20 01:43 - 2013-05-02 12:01 - 02103040 ____A (Waves Audio Ltd.) C:\Windows\System32\WavesGUILib64.dll
2013-06-20 01:43 - 2013-04-30 19:53 - 03693640 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RtkAPO64.dll
2013-06-20 01:43 - 2013-04-30 14:28 - 00916016 ____A (Sony Corporation) C:\Windows\System32\SFSS_APO.dll
2013-06-20 01:43 - 2013-04-24 17:16 - 01662024 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RTSnMg64.cpl
2013-06-20 01:43 - 2013-04-23 00:40 - 02735648 ____A (Fortemedia Corporation) C:\Windows\System32\FMAPO64.dll
2013-06-20 01:43 - 2013-04-01 14:06 - 02079816 ____A (Realtek Semiconductor Corp.) C:\Windows\RtlExUpd.dll
2013-06-20 01:43 - 2013-03-23 03:43 - 00208072 ____A (Andrea Electronics Corporation) C:\Windows\System32\AERTAC64.dll
2013-06-20 01:43 - 2013-02-20 18:55 - 01284680 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\RTCOM64.dll
2013-06-20 01:43 - 2012-10-02 14:41 - 00501192 ____A (DTS) C:\Windows\System32\DTSU2PLFX64.dll
2013-06-20 01:43 - 2012-10-02 14:41 - 00487368 ____A (DTS) C:\Windows\System32\DTSU2PGFX64.dll
2013-06-20 01:43 - 2012-10-02 14:41 - 00415688 ____A (DTS) C:\Windows\System32\DTSU2PREC64.dll
2013-06-20 01:43 - 2012-08-31 19:18 - 07164176 ____A (Dolby Laboratories) C:\Windows\System32\R4EEP64A.dll
2013-06-20 01:43 - 2012-08-31 19:17 - 00434960 ____A (Dolby Laboratories) C:\Windows\System32\R4EED64A.dll
2013-06-20 01:43 - 2012-08-31 19:17 - 00141584 ____A (Dolby Laboratories) C:\Windows\System32\R4EEL64A.dll
2013-06-20 01:43 - 2012-08-31 19:17 - 00124176 ____A (Dolby Laboratories) C:\Windows\System32\R4EEA64A.dll
2013-06-20 01:43 - 2012-08-31 19:17 - 00075024 ____A (Dolby Laboratories) C:\Windows\System32\R4EEG64A.dll
2013-06-19 22:15 - 2013-05-13 15:15 - 00016344 ____A (Intel Corporation) C:\Windows\System32\Drivers\IntelMEFWVer.dll
2013-06-19 22:12 - 2013-06-19 22:12 - 04876072 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-16 12:18 - 2013-05-31 01:24 - 01257472 ____A (Microsoft Corporation) C:\Windows\System32\kernel32.dll
2013-06-16 12:18 - 2013-05-31 01:08 - 00974848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2013-06-16 12:18 - 2013-05-24 01:01 - 01300992 ____A (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2013-06-16 12:18 - 2013-05-24 00:27 - 01022464 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2013-06-16 12:17 - 2013-05-15 04:25 - 00888320 ____A (Microsoft Corporation) C:\Windows\System32\autochk.exe
2013-06-16 12:17 - 2013-05-15 04:25 - 00542208 ____A (Microsoft Corporation) C:\Windows\System32\untfs.dll
2013-06-16 12:17 - 2013-05-15 04:24 - 00793088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\autochk.exe
2013-06-16 12:17 - 2013-05-15 04:24 - 00482816 ____A (Microsoft Corporation) C:\Windows\SysWOW64\untfs.dll
2013-06-15 16:53 - 2013-05-04 09:58 - 00120736 ____A (Microsoft Corporation) C:\Windows\System32\AuthHost.exe
2013-06-15 16:53 - 2013-05-04 09:34 - 00446720 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\USBHUB3.SYS
2013-06-15 16:53 - 2013-05-04 09:34 - 00284416 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\spaceport.sys
2013-06-15 16:53 - 2013-05-04 09:34 - 00213248 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\UCX01000.SYS
2013-06-15 16:53 - 2013-05-04 09:30 - 00058312 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2013-06-15 16:53 - 2013-05-04 08:59 - 13644288 ____A (Microsoft Corporation) C:\Windows\System32\Windows.UI.Xaml.dll
2013-06-15 16:53 - 2013-05-04 08:59 - 03241472 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2013-06-15 16:53 - 2013-05-04 08:59 - 01619968 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2013-06-15 16:53 - 2013-05-04 08:59 - 01483776 ____A (Microsoft Corporation) C:\Windows\System32\VSSVC.exe
2013-06-15 16:53 - 2013-05-04 08:59 - 00812544 ____A (Microsoft Corporation) C:\Windows\System32\Magnify.exe
2013-06-15 16:53 - 2013-05-04 08:59 - 00760320 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2013-06-15 16:53 - 2013-05-04 08:59 - 00251904 ____A (Microsoft Corporation) C:\Windows\System32\WUSettingsProvider.dll
2013-06-15 16:53 - 2013-05-04 08:59 - 00141824 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2013-06-15 16:53 - 2013-05-04 08:59 - 00098304 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2013-06-15 16:53 - 2013-05-04 08:59 - 00039424 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2013-06-15 16:53 - 2013-05-04 08:58 - 10116096 ____A (Microsoft Corporation) C:\Windows\System32\twinui.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 01332736 ____A (Microsoft Corporation) C:\Windows\System32\sysmain.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 00470528 ____A (Microsoft Corporation) C:\Windows\System32\netprofmsvc.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 00330240 ____A (Microsoft Corporation) C:\Windows\System32\stobject.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 00328192 ____A (Microsoft Corporation) C:\Windows\System32\ubpm.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 00173568 ____A (Microsoft Corporation) C:\Windows\System32\storewuauth.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 00169984 ____A (Microsoft Corporation) C:\Windows\System32\netplwiz.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 00151552 ____A (Microsoft Corporation) C:\Windows\System32\netprofm.dll
2013-06-15 16:53 - 2013-05-04 08:58 - 00093696 ____A (Microsoft Corporation) C:\Windows\System32\psmsrv.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 02305024 ____A (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 01131520 ____A (Microsoft Corporation) C:\Windows\System32\AppXDeploymentServer.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00820736 ____A (Microsoft Corporation) C:\Windows\System32\gpprefcl.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00708096 ____A (Microsoft Corporation) C:\Windows\System32\AppXDeploymentExtensions.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00560640 ____A (Microsoft Corporation) C:\Windows\System32\mfmp4srcsnk.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00501760 ____A (Microsoft Corporation) C:\Windows\System32\DevicePairing.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00389120 ____A (Microsoft Corporation) C:\Windows\System32\BCP47Langs.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00179712 ____A (Microsoft Corporation) C:\Windows\System32\bisrv.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00122368 ____A (Microsoft Corporation) C:\Windows\System32\biwinrt.dll
2013-06-15 16:53 - 2013-05-04 08:57 - 00017408 ____A (Microsoft Corporation) C:\Windows\System32\muifontsetup.dll
2013-06-15 16:53 - 2013-05-04 08:56 - 00419840 ____A (Microsoft Corporation) C:\Windows\System32\intl.cpl
2013-06-15 16:53 - 2013-05-04 06:58 - 00758784 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Magnify.exe
2013-06-15 16:53 - 2013-05-04 06:58 - 00621056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2013-06-15 16:53 - 2013-05-04 06:58 - 00125952 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2013-06-15 16:53 - 2013-05-04 06:58 - 00083968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2013-06-15 16:53 - 2013-05-04 06:58 - 00034304 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2013-06-15 16:53 - 2013-05-04 06:57 - 10788864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2013-06-15 16:53 - 2013-05-04 06:57 - 08857088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2013-06-15 16:53 - 2013-05-04 06:57 - 00303616 ____A (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2013-06-15 16:53 - 2013-05-04 06:57 - 00247296 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ubpm.dll
2013-06-15 16:53 - 2013-05-04 06:57 - 00151040 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netplwiz.dll
2013-06-15 16:53 - 2013-05-04 06:57 - 00115712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netprofm.dll
2013-06-15 16:53 - 2013-05-04 06:57 - 00018432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\npmproxy.dll
2013-06-15 16:53 - 2013-05-04 06:57 - 00014336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\muifontsetup.dll
2013-06-15 16:53 - 2013-05-04 06:56 - 02035712 ____A (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2013-06-15 16:53 - 2013-05-04 06:56 - 00582144 ____A (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
2013-06-15 16:53 - 2013-05-04 06:56 - 00449536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
2013-06-15 16:53 - 2013-05-04 06:56 - 00411136 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2013-06-15 16:53 - 2013-05-04 06:56 - 00309760 ____A (Microsoft Corporation) C:\Windows\SysWOW64\BCP47Langs.dll
2013-06-15 16:53 - 2013-05-04 06:56 - 00092160 ____A (Microsoft Corporation) C:\Windows\SysWOW64\biwinrt.dll
2013-06-15 16:53 - 2013-05-04 06:55 - 00389632 ____A (Microsoft Corporation) C:\Windows\SysWOW64\intl.cpl
2013-06-15 16:53 - 2013-05-04 06:51 - 00014848 ____A (Microsoft) C:\Windows\System32\rars.rs
2013-06-15 16:53 - 2013-05-04 06:48 - 00083968 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidclass.sys
2013-06-15 16:53 - 2013-05-04 06:48 - 00027648 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\hidusb.sys
2013-06-15 16:53 - 2013-05-04 06:47 - 00427520 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdbss.sys
2013-06-15 16:53 - 2013-05-04 06:10 - 00014848 ____A (Microsoft) C:\Windows\SysWOW64\rars.rs
2013-06-15 16:53 - 2013-05-03 00:04 - 00386646 ____A C:\Windows\System32\ApnDatabase.xml
2013-06-12 14:19 - 2013-04-03 01:37 - 00025088 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 14:19 - 2013-04-03 01:12 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 09:50 - 2013-06-05 00:09 - 00693112 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 09:50 - 2013-06-05 00:09 - 00078200 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 09:31 - 2013-05-16 00:37 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2013-06-12 09:31 - 2013-05-16 00:36 - 14320640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-12 09:31 - 2013-05-16 00:35 - 19230720 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-12 09:31 - 2013-05-16 00:35 - 00053760 ____A (Microsoft Corporation) C:\Windows\System32\UXInit.dll
2013-06-12 09:31 - 2013-05-14 15:14 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-12 09:31 - 2013-05-14 11:23 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-12 09:31 - 2013-05-04 09:45 - 02233600 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 09:31 - 2013-04-29 00:30 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-12 09:31 - 2013-04-29 00:30 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 09:31 - 2013-04-29 00:30 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-12 09:31 - 2013-04-29 00:30 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 09:31 - 2013-04-29 00:30 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-12 09:31 - 2013-04-29 00:30 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 09:31 - 2013-04-29 00:30 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 09:31 - 2013-04-29 00:28 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 09:31 - 2013-04-29 00:28 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 09:31 - 2013-04-29 00:28 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-12 09:31 - 2013-04-29 00:28 - 00915968 ____A (Microsoft Corporation) C:\Windows\System32\uxtheme.dll
2013-06-12 09:31 - 2013-04-29 00:28 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 09:31 - 2013-04-29 00:28 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 09:31 - 2013-04-29 00:27 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-12 09:31 - 2013-04-29 00:27 - 02647552 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-12 09:31 - 2013-04-29 00:27 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 09:31 - 2013-04-27 07:20 - 00733184 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 09:31 - 2013-04-24 01:13 - 01013248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 09:31 - 2013-04-24 01:12 - 01569792 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 09:31 - 2013-04-24 01:12 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 09:31 - 2013-04-24 00:56 - 01255936 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 09:31 - 2013-04-24 00:55 - 01889280 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 09:31 - 2013-04-24 00:55 - 00141312 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 09:31 - 2013-04-24 00:55 - 00068096 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
==================== One Month Modified Files and Folders =======
2013-07-07 21:13 - 2013-07-07 21:13 - 00000000 ____D C:\FRST
2013-07-07 12:27 - 2013-01-06 17:49 - 00753134 ____A C:\Windows\System32\perfh007.dat
2013-07-07 12:27 - 2013-01-06 17:49 - 00155826 ____A C:\Windows\System32\perfc007.dat
2013-07-07 12:27 - 2012-07-26 09:28 - 01745416 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-07 12:26 - 2013-07-07 12:26 - 00001057 ____A C:\Users\Peter\Desktop\JRT.txt
2013-07-07 12:24 - 2013-07-07 12:24 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\Peter\Desktop\JRT.exe
2013-07-07 12:24 - 2013-07-07 12:24 - 00000000 ____D C:\Windows\ERUNT
2013-07-07 12:24 - 2013-07-07 12:24 - 00000000 ____D C:\JRT
2013-07-07 12:22 - 2013-07-07 12:22 - 00002934 ____A C:\Users\Peter\Desktop\AdwCleaner[S1].txt
2013-07-07 12:22 - 2013-01-06 04:42 - 00000000 ___RD C:\Users\Peter\Dropbox
2013-07-07 12:22 - 2013-01-06 04:40 - 00000000 ____D C:\Users\Peter\AppData\Roaming\Dropbox
2013-07-07 12:22 - 2012-07-26 09:22 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-07 12:21 - 2013-07-07 12:21 - 00002934 ____A C:\AdwCleaner[S1].txt
2013-07-07 12:21 - 2012-07-26 07:26 - 00786432 __ASH C:\Windows\System32\config\BBI
2013-07-07 12:20 - 2013-07-07 12:20 - 00650027 ____A C:\Users\Peter\Desktop\adwcleaner.exe
2013-07-07 12:00 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\sru
2013-07-07 11:41 - 2013-01-06 03:42 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-07 10:50 - 2013-07-07 11:38 - 01934636 ____A (Farbar) C:\Users\Peter\Desktop\FRST64.exe
2013-07-07 02:25 - 2013-01-06 09:02 - 01957727 ____A C:\Windows\WindowsUpdate.log
2013-07-07 00:32 - 2013-07-07 00:32 - 00000000 ____D C:\Program Files (x86)\ThinkPad
2013-07-07 00:32 - 2013-01-06 08:52 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-07 00:32 - 2013-01-06 08:52 - 00000000 ____D C:\Program Files\Lenovo
2013-07-07 00:32 - 2013-01-06 08:52 - 00000000 ____D C:\Program Files (x86)\Lenovo
2013-07-07 00:32 - 2012-07-26 10:12 - 00000000 __RSD C:\Windows\Media
2013-07-07 00:27 - 2012-09-13 20:32 - 00577344 ____A C:\Windows\PFRO.log
2013-07-07 00:25 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\System32\NDF
2013-07-06 22:46 - 2013-07-06 22:46 - 00000000 ____D C:\Users\Peter\AppData\Roaming\Malwarebytes
2013-07-06 22:45 - 2013-07-06 22:45 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-07-06 22:13 - 2013-01-06 09:56 - 00000000 ____D C:\Users\Peter\AppData\Local\Adobe
2013-07-05 23:13 - 2013-01-06 03:39 - 00000000 ____D C:\Users\Peter\AppData\Roaming\vlc
2013-07-05 09:54 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent
2013-07-04 09:08 - 2012-07-26 09:21 - 00057789 ____A C:\Windows\setupact.log
2013-07-04 09:07 - 2013-01-18 20:37 - 00001432 ____A C:\Windows\Synaptics.log
2013-07-04 09:07 - 2013-01-06 08:51 - 00267496 ____A C:\Windows\DPINST.LOG
2013-07-04 01:08 - 2013-05-17 09:55 - 524288848 ____A C:\Users\Peter\Desktop\Firefox.ard
2013-07-04 01:08 - 2013-01-06 02:57 - 00000000 ____D C:\Users\Peter\AppData\Roaming\Mozilla
2013-07-03 23:06 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing
2013-07-03 18:25 - 2013-07-03 18:25 - 00606352 ____A C:\Users\Peter\Desktop\Passbild-36aGenerator.exe
2013-07-03 18:25 - 2013-07-03 18:25 - 00000000 ____D C:\Users\Peter\AppData\Local\Passbild_Generator
2013-07-02 16:07 - 2013-01-06 02:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-02 15:56 - 2013-04-29 16:21 - 00000000 ____D C:\Users\Peter\Documents\Citavi 4
2013-07-02 15:17 - 2013-07-02 15:17 - 00000000 ____D C:\Windows\msagent
2013-07-02 15:17 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\Help
2013-06-26 11:12 - 2013-06-26 11:12 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-06-26 10:23 - 2013-05-07 18:40 - 00083672 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys
2013-06-25 20:42 - 2013-06-25 19:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-25 09:53 - 2013-01-20 23:55 - 00000000 ____D C:\Users\Peter\Desktop\Tattoo
2013-06-25 09:20 - 2013-01-06 09:19 - 00000000 ____D C:\Users\Peter\AppData\Roaming\Adobe
2013-06-25 09:20 - 2013-01-06 08:57 - 00000000 ____D C:\ProgramData\Adobe
2013-06-25 09:16 - 2013-01-06 08:57 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-06-22 20:29 - 2013-03-19 01:29 - 00000000 ____D C:\Program Files\Intel
2013-06-22 20:29 - 2013-03-04 02:03 - 00000000 ____D C:\ProgramData\Package Cache
2013-06-22 20:28 - 2013-01-18 20:39 - 00000000 ____D C:\Program Files (x86)\Cisco
2013-06-22 20:28 - 2013-01-06 08:51 - 00000000 ____D C:\ProgramData\Intel
2013-06-22 20:28 - 2013-01-06 08:51 - 00000000 ____D C:\Program Files (x86)\Intel
2013-06-20 16:23 - 2013-06-20 16:23 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2013-06-20 16:23 - 2013-06-20 16:23 - 00000000 ____D C:\Program Files\iTunes
2013-06-20 16:23 - 2013-06-20 16:23 - 00000000 ____D C:\Program Files\iPod
2013-06-20 16:23 - 2013-05-16 23:03 - 00000000 ____D C:\Program Files (x86)\iTunes
2013-06-20 16:22 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\LiveKernelReports
2013-06-20 01:43 - 2013-06-20 01:43 - 00000000 ____D C:\Program Files (x86)\Dolby Home Theater v4
2013-06-20 01:43 - 2013-01-06 08:53 - 00003066 ____A C:\RHDSetup.log
2013-06-20 01:43 - 2013-01-06 08:53 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2013-06-19 22:12 - 2013-06-19 22:12 - 04876072 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-19 21:41 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\rescache
2013-06-19 01:42 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\WinStore
2013-06-19 01:42 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\ToastData
2013-06-19 01:42 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2013-06-19 01:42 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2013-06-19 01:42 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\SysWOW64\Dism
2013-06-19 01:42 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\System32\Dism
2013-06-18 12:49 - 2013-01-06 10:03 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-17 14:59 - 2013-01-06 14:39 - 00000000 ____D C:\Users\Peter\AppData\Local\CrashDumps
2013-06-10 00:28 - 2013-03-09 21:44 - 00000000 ____D C:\Program Files (x86)\Steam
2013-06-09 17:18 - 2013-01-24 14:03 - 00000000 ___RD C:\Users\Peter\Desktop\jpgcompressor
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-07-01 22:54
==================== End Of Log ============================ --- --- ---
--- --- ---
schon mal vielen vielen Dank für deine Hilfe =) |