ennachen | 11.12.2013 18:57 | Da scheint noch was zu sein: Code:
Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/
Windows Version: Windows 7 Home Premium
Program started at: 12/11/2013 03:37:30 PM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\
* Shortcut Cleaned: C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk => C:\Program Files (x86)\Mozilla Firefox\firefox.exe hxxp://www.nationzoom.com/?type=sc&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Jeanette\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
Searching C:\Users\Public\Desktop\
Searching C:\Users\Jeanette\Desktop
1 bad shortcut found.
Program finished at: 12/11/2013 03:37:50 PM
Execution time: 0 hours(s), 0 minute(s), and 20 seconds(s)
Frst:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-12-2013 2
Ran by Jeanette (administrator) on KASSIOPEIA on 11-12-2013 15:38:30
Running from C:\Users\Jeanette\Desktop
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\mDNSResponder.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\tunmgr.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\BbDevMgr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(Dropbox, Inc.) C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Internet\Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11725928 2010-12-23] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2186856 2010-12-10] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2101032 2010-05-03] (Synaptics Incorporated)
HKLM\...\Run: [SynBtnAsst] - C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe [54568 2010-05-03] (Synaptics Incorporated)
HKLM\...\Run: [OnekeyStudio] - C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789920 2011-05-17] (Lenovo)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4448704 2010-03-11] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056832 2010-03-11] (Lenovo (Beijing) Limited)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
MountPoints2: F - F:\AutoRun.exe setup.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-06-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [MuteSync] - C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe [336384 2009-12-28] (Lenovo)
HKLM-x32\...\Run: [Lenovo SplitScreen] - C:\Program Files\Lenovo\Lenovo SplitScreen\SplitScreen\AutoRunSpS.exe [778592 2010-06-23] (Lenovo)
HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167008 2010-02-03] (CyberLink Corp.)
HKLM-x32\...\Run: [Lenovo SlideNav2] - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe [318400 2009-12-30] (Lenovo)
HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-10-26] (Nullsoft, Inc.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] - C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe [443408 2013-09-09] (Research In Motion Limited)
HKLM-x32\...\Run: [RIM PeerManager] - C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe [4424704 2013-11-05] (Research In Motion Limited)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-07] (AVAST Software)
HKU\Christoph\...\Run: [BlackBerryLink.exe] - C:\Program Files (x86)\Research In Motion\BlackBerry Link\BlackBerryLink.exe [1450000 2013-11-06] (Research In Motion)
HKU\Christoph\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\Default\...\RunOnce: [LenovoWallpaper] - C:\Program Files\desktop\ChangeDesktop.exe [53760 2009-09-30] ()
HKU\Default User\...\RunOnce: [LenovoWallpaper] - C:\Program Files\desktop\ChangeDesktop.exe [53760 2009-09-30] ()
AppInit_DLLs: [ ] ()
Startup: C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {94bd6970-1a83-41dc-9be5-bf50b3d0238f} URL =
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Jeanette\AppData\Roaming\Mozilla\Firefox\Profiles\kjjq5rtn.default
FF NewTab: hxxp://www.google.com/firefox
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: langpack-sv-SE - C:\Users\Jeanette\AppData\Roaming\Mozilla\Firefox\Profiles\kjjq5rtn.default\Extensions\langpack-sv-SE@firefox.mozilla.org.xpi
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
==================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-07] (AVAST Software)
R3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2013-09-09] (Research In Motion Limited)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [873248 2010-01-12] (Broadcom Corporation.)
S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-15] (Lenovo Group Limited)
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [575304 2009-11-17] (Lenovo Group Limited)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-15] (Lenovo Group Limited)
R2 RIM MDNS; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [389632 2013-11-05] (Apple Inc.)
R2 RIM Tunnel Service; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1286656 2013-11-05] (Research In Motion Limited)
R2 Slidebar Notifier Service; C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe [69568 2009-12-30] (Lenovo)
S2 Bonjour Service; "C:\Program Files (x86)\Bonjour\mDNSResponder.exe" [x]
==================== Drivers (Whitelisted) ====================
S1 acedrv07; C:\windows\system32\drivers\acedrv07.sys [125440 2013-01-13] ()
S3 AF15BDA; C:\Windows\System32\DRIVERS\AF15BDA.sys [368832 2009-11-05] (AfaTech )
R2 aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [38984 2013-12-07] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-12-07] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-12-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-07] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1032416 2013-12-07] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [409832 2013-12-07] (AVAST Software)
R1 aswTdi; C:\windows\system32\drivers\aswTdi.sys [65264 2013-12-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-07] ()
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-06-06] (DT Soft Ltd)
S3 ezplay; C:\Windows\System32\Drivers\ezplay.sys [118400 2011-10-06] (VSO Software)
R3 JmUsbCcgp; C:\Windows\System32\DRIVERS\jmccgp.sys [17904 2010-02-05] (JMicron Technology Corp.)
R3 JmUsbVideo; C:\Windows\System32\Drivers\jmcam.sys [56688 2010-02-05] (JMicron Technology Corp.)
R3 JmUsbVideo2; C:\Windows\System32\Drivers\jmcam_lo.sys [31088 2010-02-05] (JMicron Technology Corp.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2013-06-27] (Research In Motion Limited)
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920 2013-11-05] (Research in Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [113704 2008-10-21] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-10-21] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [152616 2008-10-21] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-10-21] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [128552 2008-10-21] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [145960 2008-10-21] (MCCI Corporation)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo)
U3 BcmSqlStartupSvc;
U2 IviRegMgr;
U2 RichVideo;
S2 sbapifs; system32\DRIVERS\sbapifs.sys [x]
U3 SQLWriter;
S3 zlportio; \??\C:\Program Files (x86)\UltraStar\zlportio.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-11 15:38 - 2013-12-11 15:38 - 00021667 _____ C:\Users\Jeanette\Desktop\FRST.txt
2013-12-11 15:37 - 2013-12-11 15:37 - 00002324 _____ C:\sc-cleaner.txt
2013-12-11 15:19 - 2013-12-11 15:19 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Jeanette\Desktop\sc-cleaner.exe
2013-12-09 23:30 - 2013-12-09 23:30 - 00891184 _____ C:\Users\Jeanette\Desktop\SecurityCheck.exe
2013-12-09 20:04 - 2013-12-09 20:04 - 02347384 _____ (ESET) C:\Users\Jeanette\Desktop\esetsmartinstaller_enu.exe
2013-12-09 16:03 - 2013-12-11 15:36 - 00000000 ___RD C:\Users\Jeanette\Dropbox
2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-09 15:59 - 2013-12-11 15:36 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Dropbox
2013-12-08 19:39 - 2013-12-08 19:39 - 00000000 ____D C:\windows\ERUNT
2013-12-08 18:55 - 2013-12-08 18:55 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-08 18:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-12-08 18:53 - 2013-12-08 18:53 - 01034531 _____ (Thisisu) C:\Users\Jeanette\Desktop\JRT.exe
2013-12-08 16:05 - 2013-12-08 16:05 - 04286464 _____ C:\Users\Jeanette\Downloads\anyconnect-win-3.1.04059-pre-deploy-k9.msi
2013-12-08 15:22 - 2013-12-10 08:20 - 00009166 _____ C:\windows\PFRO.log
2013-12-08 09:44 - 2013-12-08 09:44 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\AVAST Software
2013-12-07 21:34 - 2013-12-07 21:35 - 00049358 _____ C:\Users\Jeanette\Downloads\FRST.txt
2013-12-07 21:29 - 2013-12-07 21:29 - 00000186 _____ C:\Users\Jeanette\defogger_reenable
2013-12-07 18:43 - 2013-12-07 18:43 - 00000938 _____ C:\Users\Public\Desktop\Loaris Trojan Remover.lnk
2013-12-07 18:43 - 2013-12-07 18:43 - 00000000 ____D C:\Program Files\Loaris
2013-12-07 17:58 - 2013-12-07 18:01 - 00007512 _____ C:\Users\Jeanette\Downloads\SystemLook.txt
2013-12-07 17:57 - 2013-12-07 17:57 - 00165376 _____ C:\Users\Jeanette\Desktop\SystemLook_x64.exe
2013-12-07 17:40 - 2013-12-07 17:40 - 00000000 ____D C:\FRST
2013-12-07 17:39 - 2013-12-07 17:39 - 01927514 _____ (Farbar) C:\Users\Jeanette\Desktop\FRST64.exe
2013-12-07 17:32 - 2013-12-11 15:35 - 00000952 _____ C:\windows\setupact.log
2013-12-07 17:32 - 2013-12-07 17:32 - 00000000 _____ C:\windows\setuperr.log
2013-12-07 17:30 - 2013-12-07 17:30 - 00260376 _____ C:\Users\Jeanette\Documents\cc_20131207_173006.reg
2013-12-07 17:20 - 2013-12-07 17:20 - 00002778 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2013-12-07 17:16 - 2013-12-07 17:20 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-07 16:49 - 2013-12-08 19:26 - 00000000 ____D C:\AdwCleaner
2013-12-07 16:36 - 2013-12-07 16:37 - 01110034 _____ C:\Users\Jeanette\Desktop\AdwCleaner-3.014.exe
2013-12-07 15:32 - 2013-12-07 15:32 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\AVAST Software
2013-12-07 15:22 - 2013-12-07 15:22 - 00000192 _____ C:\windows\system32\Drivers\kgpfr2.cfg
2013-12-07 15:19 - 2013-12-10 19:09 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-12-07 15:19 - 2013-12-07 15:19 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-07 15:19 - 2013-12-07 15:19 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065264 _____ (AVAST Software) C:\windows\system32\Drivers\aswTdi.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-07 15:19 - 2013-12-07 15:19 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-12-07 15:18 - 2013-12-07 15:18 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-07 15:15 - 2013-12-07 15:15 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-07 15:01 - 2013-12-07 15:01 - 00001136 _____ C:\windows\system32\Drivers\kgpcpy.cfg
2013-12-07 15:01 - 2013-12-07 15:01 - 00000168 _____ C:\windows\SysWOW64\Drivers\kgpfr2.cfg
2013-12-07 15:00 - 2013-12-07 15:35 - 00000000 ____D C:\Program Files (x86)\STOPzilla!
2013-12-07 00:46 - 2013-12-07 09:25 - 00000000 ____D C:\Program Files (x86)\Re-markit
2013-12-07 00:01 - 2013-12-07 00:02 - 00000000 ____D C:\Users\Jeanette\Documents\Spannendes
2013-12-06 21:28 - 2013-12-06 21:44 - 628231075 _____ C:\Users\Jeanette\Downloads\LEGOMarvelDemo.zip
2013-12-06 21:19 - 2013-12-06 21:20 - 64790176 _____ (Rovio Entertainment Ltd.) C:\Users\Jeanette\Downloads\AngryBirdsRioInstaller_1.7.1.exe
2013-12-02 12:24 - 2013-12-02 12:25 - 36646912 _____ C:\Users\Jeanette\Downloads\ExtremeTuxRacer_0.6.0_x64.msi
2013-12-02 12:23 - 2013-12-02 12:23 - 01345613 _____ C:\Users\Jeanette\Downloads\Christmas_Font_Pack(2).zip
2013-12-01 09:59 - 2013-12-01 09:59 - 03891573 _____ C:\Users\Jeanette\Downloads\Freebie Lila-Lotta ZOO.zip
2013-11-27 19:23 - 2013-12-11 10:42 - 00000000 ____D C:\Users\Jeanette\Documents\Citavi 4
2013-11-27 18:22 - 2013-11-27 18:23 - 00000000 ____D C:\Program Files (x86)\Citavi 4
2013-11-27 15:09 - 2013-11-27 15:09 - 00003426 _____ C:\Users\Jeanette\Downloads\citavi-einstellungsdatei.csd
2013-11-27 10:51 - 2013-11-27 10:51 - 00107520 _____ C:\Users\Jeanette\Downloads\2013.11.17_G2-Adressen.xls
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\SZKG64.sys
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\is3srv64.sys
2013-11-18 21:57 - 2013-11-18 21:57 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Adobe_Systems_Incorporate
2013-11-18 21:56 - 2013-11-18 21:56 - 00002178 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
2013-11-18 19:17 - 2013-11-29 12:06 - 00015405 _____ C:\Users\Jeanette\Documents\Adressliste Katzengruppeteil 1.xlsx
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BLACKBERRY-47A9
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BlackBerry
2013-11-13 20:08 - 2013-11-13 20:08 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\XCPCSync.OEM
2013-11-13 20:07 - 2013-11-13 20:11 - 00000000 ____D C:\Users\Christoph\AppData\Local\Research In Motion
2013-11-13 20:07 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\Research In Motion
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00002225 _____ C:\Users\Public\Desktop\BlackBerry Link.lnk
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____D C:\ProgramData\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\out.txt
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\err.txt
2013-11-13 20:06 - 2012-12-10 15:48 - 00044544 _____ (Research in Motion Ltd) C:\windows\system32\Drivers\RimSerial_AMD64.sys
2013-11-13 20:05 - 2013-11-13 20:05 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2013-11-13 19:58 - 2013-11-13 19:58 - 13462360 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage(1).exe.part
2013-11-13 19:57 - 2013-11-13 20:01 - 164855312 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage.exe
2013-11-13 11:29 - 2013-11-13 11:29 - 00000000 ____D C:\windows\SysWOW64\20-20 Technologies
2013-11-12 14:35 - 2013-11-12 14:35 - 00000000 ____D C:\ProgramData\Oracle
2013-11-12 14:27 - 2013-11-12 14:26 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-12 10:59 - 2013-11-12 10:59 - 02594735 _____ C:\Users\Jeanette\Downloads\Fuchs-stundenplan.zip
2013-11-11 09:24 - 2013-12-11 15:37 - 00001887 _____ C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
==================== One Month Modified Files and Folders =======
2013-12-11 15:39 - 2013-12-11 15:38 - 00021667 _____ C:\Users\Jeanette\Desktop\FRST.txt
2013-12-11 15:37 - 2013-12-11 15:37 - 00002324 _____ C:\sc-cleaner.txt
2013-12-11 15:37 - 2013-11-11 09:24 - 00001887 _____ C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-12-11 15:36 - 2013-12-09 16:03 - 00000000 ___RD C:\Users\Jeanette\Dropbox
2013-12-11 15:36 - 2013-12-09 15:59 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Dropbox
2013-12-11 15:35 - 2013-12-07 17:32 - 00000952 _____ C:\windows\setupact.log
2013-12-11 15:35 - 2012-04-01 12:03 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-11 15:35 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-12-11 15:31 - 2011-05-17 16:16 - 01944079 _____ C:\windows\WindowsUpdate.log
2013-12-11 15:28 - 2011-08-19 10:07 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 15:21 - 2013-07-16 21:55 - 00000000 ____D C:\windows\system32\MRT
2013-12-11 15:21 - 2011-06-08 20:03 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-11 15:21 - 2009-07-14 05:45 - 00013424 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-11 15:21 - 2009-07-14 05:45 - 00013424 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-11 15:19 - 2013-12-11 15:19 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Jeanette\Desktop\sc-cleaner.exe
2013-12-11 15:18 - 2011-11-27 14:43 - 00000000 ____D C:\Users\Jeanette\Documents\Outlook-Dateien
2013-12-11 15:06 - 2012-04-01 12:03 - 00001114 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-11 14:51 - 2012-04-06 18:41 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-12-11 11:02 - 2012-01-09 19:25 - 00000000 ____D C:\Users\Jeanette\Documents\Citavi 3
2013-12-11 10:42 - 2013-11-27 19:23 - 00000000 ____D C:\Users\Jeanette\Documents\Citavi 4
2013-12-11 10:14 - 2011-05-17 23:46 - 00698390 _____ C:\windows\system32\perfh007.dat
2013-12-11 10:14 - 2011-05-17 23:46 - 00149054 _____ C:\windows\system32\perfc007.dat
2013-12-11 10:14 - 2009-07-14 06:13 - 01617026 _____ C:\windows\system32\PerfStringBackup.INI
2013-12-10 20:52 - 2012-04-06 18:41 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 20:52 - 2012-04-06 18:41 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 20:52 - 2011-06-08 14:22 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-10 19:09 - 2013-12-07 15:19 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-12-10 19:07 - 2009-07-14 06:08 - 00032632 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-12-10 08:20 - 2013-12-08 15:22 - 00009166 _____ C:\windows\PFRO.log
2013-12-09 23:30 - 2013-12-09 23:30 - 00891184 _____ C:\Users\Jeanette\Desktop\SecurityCheck.exe
2013-12-09 20:04 - 2013-12-09 20:04 - 02347384 _____ (ESET) C:\Users\Jeanette\Desktop\esetsmartinstaller_enu.exe
2013-12-09 16:03 - 2011-06-05 09:16 - 00000000 ____D C:\Users\Jeanette
2013-12-09 16:01 - 2011-06-05 09:17 - 00000000 ___RD C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-08 19:39 - 2013-12-08 19:39 - 00000000 ____D C:\windows\ERUNT
2013-12-08 19:26 - 2013-12-07 16:49 - 00000000 ____D C:\AdwCleaner
2013-12-08 18:55 - 2013-12-08 18:55 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-08 18:53 - 2013-12-08 18:53 - 01034531 _____ (Thisisu) C:\Users\Jeanette\Desktop\JRT.exe
2013-12-08 16:05 - 2013-12-08 16:05 - 04286464 _____ C:\Users\Jeanette\Downloads\anyconnect-win-3.1.04059-pre-deploy-k9.msi
2013-12-08 15:20 - 2009-07-14 03:34 - 00000478 _____ C:\windows\win.ini
2013-12-08 09:44 - 2013-12-08 09:44 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\AVAST Software
2013-12-07 21:35 - 2013-12-07 21:34 - 00049358 _____ C:\Users\Jeanette\Downloads\FRST.txt
2013-12-07 21:29 - 2013-12-07 21:29 - 00000186 _____ C:\Users\Jeanette\defogger_reenable
2013-12-07 20:09 - 2012-06-22 08:41 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-12-07 18:43 - 2013-12-07 18:43 - 00000938 _____ C:\Users\Public\Desktop\Loaris Trojan Remover.lnk
2013-12-07 18:43 - 2013-12-07 18:43 - 00000000 ____D C:\Program Files\Loaris
2013-12-07 18:01 - 2013-12-07 17:58 - 00007512 _____ C:\Users\Jeanette\Downloads\SystemLook.txt
2013-12-07 17:57 - 2013-12-07 17:57 - 00165376 _____ C:\Users\Jeanette\Desktop\SystemLook_x64.exe
2013-12-07 17:40 - 2013-12-07 17:40 - 00000000 ____D C:\FRST
2013-12-07 17:39 - 2013-12-07 17:39 - 01927514 _____ (Farbar) C:\Users\Jeanette\Desktop\FRST64.exe
2013-12-07 17:32 - 2013-12-07 17:32 - 00000000 _____ C:\windows\setuperr.log
2013-12-07 17:30 - 2013-12-07 17:30 - 00260376 _____ C:\Users\Jeanette\Documents\cc_20131207_173006.reg
2013-12-07 17:20 - 2013-12-07 17:20 - 00002778 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2013-12-07 17:20 - 2013-12-07 17:16 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-07 17:20 - 2012-04-17 10:58 - 00000000 ____D C:\Program Files\CCleaner
2013-12-07 16:39 - 2011-06-08 13:40 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Adobe
2013-12-07 16:37 - 2013-12-07 16:36 - 01110034 _____ C:\Users\Jeanette\Desktop\AdwCleaner-3.014.exe
2013-12-07 16:06 - 2011-06-06 11:19 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Simple Sudoku
2013-12-07 15:35 - 2013-12-07 15:00 - 00000000 ____D C:\Program Files (x86)\STOPzilla!
2013-12-07 15:32 - 2013-12-07 15:32 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\AVAST Software
2013-12-07 15:22 - 2013-12-07 15:22 - 00000192 _____ C:\windows\system32\Drivers\kgpfr2.cfg
2013-12-07 15:19 - 2013-12-07 15:19 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-07 15:19 - 2013-12-07 15:19 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065264 _____ (AVAST Software) C:\windows\system32\Drivers\aswTdi.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-07 15:19 - 2013-12-07 15:19 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-12-07 15:18 - 2013-12-07 15:18 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-07 15:15 - 2013-12-07 15:15 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-07 15:10 - 2011-09-18 14:01 - 00000000 ____D C:\windows\Minidump
2013-12-07 15:01 - 2013-12-07 15:01 - 00001136 _____ C:\windows\system32\Drivers\kgpcpy.cfg
2013-12-07 15:01 - 2013-12-07 15:01 - 00000168 _____ C:\windows\SysWOW64\Drivers\kgpfr2.cfg
2013-12-07 09:25 - 2013-12-07 00:46 - 00000000 ____D C:\Program Files (x86)\Re-markit
2013-12-07 00:02 - 2013-12-07 00:01 - 00000000 ____D C:\Users\Jeanette\Documents\Spannendes
2013-12-06 21:44 - 2013-12-06 21:28 - 628231075 _____ C:\Users\Jeanette\Downloads\LEGOMarvelDemo.zip
2013-12-06 21:20 - 2013-12-06 21:19 - 64790176 _____ (Rovio Entertainment Ltd.) C:\Users\Jeanette\Downloads\AngryBirdsRioInstaller_1.7.1.exe
2013-12-06 20:56 - 2011-06-15 09:44 - 00000000 ____D C:\Users\Jeanette\Documents\Nähen
2013-12-04 20:01 - 2012-04-01 12:03 - 00004110 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-04 20:01 - 2012-04-01 12:03 - 00003858 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-02 12:25 - 2013-12-02 12:24 - 36646912 _____ C:\Users\Jeanette\Downloads\ExtremeTuxRacer_0.6.0_x64.msi
2013-12-02 12:23 - 2013-12-02 12:23 - 01345613 _____ C:\Users\Jeanette\Downloads\Christmas_Font_Pack(2).zip
2013-12-01 09:59 - 2013-12-01 09:59 - 03891573 _____ C:\Users\Jeanette\Downloads\Freebie Lila-Lotta ZOO.zip
2013-11-29 12:06 - 2013-11-18 19:17 - 00015405 _____ C:\Users\Jeanette\Documents\Adressliste Katzengruppeteil 1.xlsx
2013-11-27 20:24 - 2012-01-09 19:25 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Swiss Academic Software
2013-11-27 19:24 - 2011-11-03 21:12 - 00000000 ____D C:\Users\Jeanette\Documents\Hannspad Backup
2013-11-27 19:19 - 2013-01-20 19:16 - 00000000 ____D C:\Users\Jeanette\Documents\Martinsverein
2013-11-27 18:26 - 2011-10-22 18:17 - 00000000 ____D C:\Users\Jeanette\AppData\Local\MediaMonkey
2013-11-27 18:26 - 2011-10-22 18:17 - 00000000 ____D C:\Program Files (x86)\MediaMonkey
2013-11-27 18:24 - 2012-01-09 19:12 - 00000000 ____D C:\ProgramData\Swiss Academic Software
2013-11-27 18:23 - 2013-11-27 18:22 - 00000000 ____D C:\Program Files (x86)\Citavi 4
2013-11-27 18:20 - 2011-09-10 11:23 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Downloaded Installations
2013-11-27 15:33 - 2011-06-06 09:18 - 00000000 ____D C:\Users\Jeanette\Documents\Youcam
2013-11-27 15:15 - 2012-07-07 08:41 - 01591306 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2013-11-27 15:09 - 2013-11-27 15:09 - 00003426 _____ C:\Users\Jeanette\Downloads\citavi-einstellungsdatei.csd
2013-11-27 10:51 - 2013-11-27 10:51 - 00107520 _____ C:\Users\Jeanette\Downloads\2013.11.17_G2-Adressen.xls
2013-11-21 08:26 - 2012-08-28 09:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-20 20:56 - 2011-06-06 09:53 - 00000000 ____D C:\Program Files (x86)\Internet
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\SZKG64.sys
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\is3srv64.sys
2013-11-19 03:33 - 2011-06-05 12:42 - 00267936 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2013-11-18 21:57 - 2013-11-18 21:57 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Adobe_Systems_Incorporate
2013-11-18 21:57 - 2011-11-27 10:44 - 00000000 ____D C:\Users\Jeanette\Documents\My Digital Editions
2013-11-18 21:56 - 2013-11-18 21:56 - 00002178 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
2013-11-18 21:56 - 2011-08-05 21:35 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-11-18 21:52 - 2012-04-03 21:57 - 00000000 ____D C:\Program Files (x86)\Purplehills
2013-11-18 19:21 - 2011-12-01 10:26 - 00000000 ____D C:\Users\Jeanette\Documents\schule
2013-11-18 17:15 - 2012-10-05 11:01 - 00000000 ____D C:\Users\Jeanette\Documents\Kita
2013-11-14 20:06 - 2011-10-15 13:52 - 00000000 ____D C:\Users\Christoph\AppData\Local\Microsoft Help
2013-11-13 20:11 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Christoph\AppData\Local\Research In Motion
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BLACKBERRY-47A9
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BlackBerry
2013-11-13 20:10 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\Research In Motion
2013-11-13 20:08 - 2013-11-13 20:08 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\XCPCSync.OEM
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00002225 _____ C:\Users\Public\Desktop\BlackBerry Link.lnk
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____D C:\ProgramData\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\out.txt
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\err.txt
2013-11-13 20:05 - 2013-11-13 20:05 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2013-11-13 20:01 - 2013-11-13 19:57 - 164855312 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage.exe
2013-11-13 19:58 - 2013-11-13 19:58 - 13462360 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage(1).exe.part
2013-11-13 11:29 - 2013-11-13 11:29 - 00000000 ____D C:\windows\SysWOW64\20-20 Technologies
2013-11-13 11:20 - 2013-10-07 12:18 - 00012086 _____ C:\Users\Jeanette\Documents\Adressvorlage neu.xlsx
2013-11-12 14:35 - 2013-11-12 14:35 - 00000000 ____D C:\ProgramData\Oracle
2013-11-12 14:26 - 2013-11-12 14:27 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-12 14:26 - 2011-06-06 11:20 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-12 10:59 - 2013-11-12 10:59 - 02594735 _____ C:\Users\Jeanette\Downloads\Fuchs-stundenplan.zip
Some content of TEMP:
====================
C:\Users\Christoph\AppData\Local\Temp\avgnt.exe
C:\Users\Christoph\AppData\Local\Temp\BlackBerryDeviceManager.exe
C:\Users\Christoph\AppData\Local\Temp\BlackBerryLauncher.exe
C:\Users\Christoph\AppData\Local\Temp\FileSystemView.dll
C:\Users\Jeanette\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-11 15:06
==================== End Of Log ============================ --- --- ---
--- --- ---
Gruß,
ennachen
SC-cleaner: Code:
Shortcut Cleaner 1.2.6 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Shortcut Cleaner can be found at this link:
hxxp://www.bleepingcomputer.com/download/shortcut-cleaner/
Windows Version: Windows 7 Home Premium
Program started at: 12/11/2013 06:52:56 PM.
Scanning for registry hijacks:
* No issues found in the Registry.
Searching for Hijacked Shortcuts:
Searching C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\
Searching C:\ProgramData\Microsoft\Windows\Start Menu\
Searching C:\Users\Jeanette\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\
Searching C:\Users\Public\Desktop\
Searching C:\Users\Jeanette\Desktop
0 bad shortcuts found.
Program finished at: 12/11/2013 06:53:10 PM
Execution time: 0 hours(s), 0 minute(s), and 14 seconds(s) Frst:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-12-2013 2
Ran by Jeanette (administrator) on KASSIOPEIA on 11-12-2013 18:54:17
Running from C:\Users\Jeanette\Desktop
Windows 7 Home Premium (X64) OS Language: German Standard
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\mDNSResponder.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\tunmgr.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\BbDevMgr.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Broadcom Corporation.) C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Dropbox, Inc.) C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe
() C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Nullsoft, Inc.) C:\Program Files (x86)\Winamp\winampa.exe
(Lenovo) C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNavigator.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Mozilla Corporation) C:\Program Files (x86)\Internet\Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Internet\Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [HotKeysCmds] - C:\windows\system32\hkcmd.exe [ ] ()
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11725928 2010-12-23] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2186856 2010-12-10] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2101032 2010-05-03] (Synaptics Incorporated)
HKLM\...\Run: [SynBtnAsst] - C:\Program Files\Synaptics\SynTP\SynBtnAsst.exe [54568 2010-05-03] (Synaptics Incorporated)
HKLM\...\Run: [OnekeyStudio] - C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe [789920 2011-05-17] (Lenovo)
HKLM\...\Run: [EnergyUtility] - C:\Program Files (x86)\Lenovo\Energy Management\utility.exe [4448704 2010-03-11] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] - C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [7056832 2010-03-11] (Lenovo (Beijing) Limited)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
MountPoints2: F - F:\AutoRun.exe setup.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-06-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [MuteSync] - C:\Program Files (x86)\Lenovo\Lenovo MuteSync\MuteSync.exe [336384 2009-12-28] (Lenovo)
HKLM-x32\...\Run: [Lenovo SplitScreen] - C:\Program Files\Lenovo\Lenovo SplitScreen\SplitScreen\AutoRunSpS.exe [778592 2010-06-23] (Lenovo)
HKLM-x32\...\Run: [UCam_Menu] - C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM-x32\...\Run: [YouCam Mirror Tray icon] - C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [167008 2010-02-03] (CyberLink Corp.)
HKLM-x32\...\Run: [Lenovo SlideNav2] - C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlideNavVDM.exe [318400 2009-12-30] (Lenovo)
HKLM-x32\...\Run: [UpdateP2GShortCut] - C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2011-10-26] (Nullsoft, Inc.)
HKLM-x32\...\Run: [BCSSync] - C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] - C:\Program Files (x86)\Common Files\Research in Motion\USB Drivers\RIMBBLaunchAgent.exe [443408 2013-09-09] (Research In Motion Limited)
HKLM-x32\...\Run: [RIM PeerManager] - C:\Program Files (x86)\Common Files\Research in Motion\Tunnel Manager\PeerManager.exe [4424704 2013-11-05] (Research In Motion Limited)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3568312 2013-12-07] (AVAST Software)
HKU\Christoph\...\Run: [BlackBerryLink.exe] - C:\Program Files (x86)\Research In Motion\BlackBerry Link\BlackBerryLink.exe [1450000 2013-11-06] (Research In Motion)
HKU\Christoph\...\Run: [OfficeSyncProcess] - C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\Default\...\RunOnce: [LenovoWallpaper] - C:\Program Files\desktop\ChangeDesktop.exe [53760 2009-09-30] ()
HKU\Default User\...\RunOnce: [LenovoWallpaper] - C:\Program Files\desktop\ChangeDesktop.exe [53760 2009-09-30] ()
AppInit_DLLs: [ ] ()
Startup: C:\Users\Christoph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk
ShortcutTarget: OpenOffice.org 3.3.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe (No File)
Startup: C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Jeanette\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.bing.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1386373571&from=tugs&uid=WDCXWD7500BPVT-24HXZT1_WD-WX61A417824278242&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/
StartMenuInternet: IEXPLORE.EXE - c:\program files (x86)\internet explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKCU - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {94bd6970-1a83-41dc-9be5-bf50b3d0238f} URL =
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - TerraTec Home Cinema - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files (x86)\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Jeanette\AppData\Roaming\Mozilla\Firefox\Profiles\kjjq5rtn.default
FF NewTab: hxxp://www.google.com/firefox
FF DefaultSearchEngine: Google
FF SearchEngineOrder.1: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de
FF Keyword.URL: hxxp://www.google.com/search?ie=UTF-8&oe=utf-8&q=
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 - C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 - C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @zylom.com/ZylomGamesPlayer - C:\ProgramData\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: langpack-sv-SE - C:\Users\Jeanette\AppData\Roaming\Mozilla\Firefox\Profiles\kjjq5rtn.default\Extensions\langpack-sv-SE@firefox.mozilla.org.xpi
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
==================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files (x86)\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2013-12-07] (AVAST Software)
R3 BlackBerry Device Manager; C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\BbDevMgr.exe [585728 2013-09-09] (Research In Motion Limited)
R2 btwdins; C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe [873248 2010-01-12] (Broadcom Corporation.)
S3 IGRS; C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-15] (Lenovo Group Limited)
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [575304 2009-11-17] (Lenovo Group Limited)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 PS_MDP; C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
S2 ReadyComm.DirectRouter; C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll [103688 2009-07-15] (Lenovo Group Limited)
R2 RIM MDNS; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\mDNSResponder.exe [389632 2013-11-05] (Apple Inc.)
R2 RIM Tunnel Service; C:\Program Files (x86)\Common Files\Research In Motion\Tunnel Manager\tunmgr.exe [1286656 2013-11-05] (Research In Motion Limited)
R2 Slidebar Notifier Service; C:\Program Files\Lenovo\Lenovo SlideNav\SlidebarNavigator\SlidebarNotifier.exe [69568 2009-12-30] (Lenovo)
S2 Bonjour Service; "C:\Program Files (x86)\Bonjour\mDNSResponder.exe" [x]
==================== Drivers (Whitelisted) ====================
S1 acedrv07; C:\windows\system32\drivers\acedrv07.sys [125440 2013-01-13] ()
S3 AF15BDA; C:\Windows\System32\DRIVERS\AF15BDA.sys [368832 2009-11-05] (AfaTech )
R2 aswFsBlk; C:\windows\system32\drivers\aswFsBlk.sys [38984 2013-12-07] (AVAST Software)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [84328 2013-12-07] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [92544 2013-12-07] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-07] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [1032416 2013-12-07] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [409832 2013-12-07] (AVAST Software)
R1 aswTdi; C:\windows\system32\drivers\aswTdi.sys [65264 2013-12-07] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [205320 2013-12-07] ()
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [79376 2009-07-16] (Lenovo)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2011-06-06] (DT Soft Ltd)
S3 ezplay; C:\Windows\System32\Drivers\ezplay.sys [118400 2011-10-06] (VSO Software)
R3 JmUsbCcgp; C:\Windows\System32\DRIVERS\jmccgp.sys [17904 2010-02-05] (JMicron Technology Corp.)
R3 JmUsbVideo; C:\Windows\System32\Drivers\jmcam.sys [56688 2010-02-05] (JMicron Technology Corp.)
R3 JmUsbVideo2; C:\Windows\System32\Drivers\jmcam_lo.sys [31088 2010-02-05] (JMicron Technology Corp.)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [79872 2013-06-27] (Research In Motion Limited)
R3 rimvndis; C:\Windows\System32\Drivers\rimvndis6_AMD64.sys [17920 2013-11-05] (Research in Motion Limited)
R3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44544 2012-12-10] (Research in Motion Ltd)
S3 s0017bus; C:\Windows\System32\DRIVERS\s0017bus.sys [113704 2008-10-21] (MCCI Corporation)
S3 s0017mdfl; C:\Windows\System32\DRIVERS\s0017mdfl.sys [19496 2008-10-21] (MCCI Corporation)
S3 s0017mdm; C:\Windows\System32\DRIVERS\s0017mdm.sys [152616 2008-10-21] (MCCI Corporation)
S3 s0017mgmt; C:\Windows\System32\DRIVERS\s0017mgmt.sys [133160 2008-10-21] (MCCI Corporation)
S3 s0017nd5; C:\Windows\System32\DRIVERS\s0017nd5.sys [34856 2008-10-21] (MCCI Corporation)
S3 s0017obex; C:\Windows\System32\DRIVERS\s0017obex.sys [128552 2008-10-21] (MCCI Corporation)
S3 s0017unic; C:\Windows\System32\DRIVERS\s0017unic.sys [145960 2008-10-21] (MCCI Corporation)
S3 usbrndis6; C:\Windows\System32\DRIVERS\usb80236.sys [19968 2013-02-12] (Microsoft Corporation)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11280 2009-07-16] (Lenovo)
U3 BcmSqlStartupSvc;
U2 IviRegMgr;
U2 RichVideo;
S2 sbapifs; system32\DRIVERS\sbapifs.sys [x]
U3 SQLWriter;
S3 zlportio; \??\C:\Program Files (x86)\UltraStar\zlportio.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-12-11 18:54 - 2013-12-11 18:54 - 00022197 _____ C:\Users\Jeanette\Desktop\FRST.txt
2013-12-11 15:37 - 2013-12-11 18:53 - 00001788 _____ C:\sc-cleaner.txt
2013-12-11 15:19 - 2013-12-11 15:19 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Jeanette\Desktop\sc-cleaner.exe
2013-12-09 23:30 - 2013-12-09 23:30 - 00891184 _____ C:\Users\Jeanette\Desktop\SecurityCheck.exe
2013-12-09 20:04 - 2013-12-09 20:04 - 02347384 _____ (ESET) C:\Users\Jeanette\Desktop\esetsmartinstaller_enu.exe
2013-12-09 16:03 - 2013-12-11 18:40 - 00000000 ___RD C:\Users\Jeanette\Dropbox
2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-09 15:59 - 2013-12-11 18:40 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Dropbox
2013-12-08 19:39 - 2013-12-08 19:39 - 00000000 ____D C:\windows\ERUNT
2013-12-08 18:55 - 2013-12-08 18:55 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-08 18:55 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2013-12-08 18:53 - 2013-12-08 18:53 - 01034531 _____ (Thisisu) C:\Users\Jeanette\Desktop\JRT.exe
2013-12-08 16:05 - 2013-12-08 16:05 - 04286464 _____ C:\Users\Jeanette\Downloads\anyconnect-win-3.1.04059-pre-deploy-k9.msi
2013-12-08 15:22 - 2013-12-10 08:20 - 00009166 _____ C:\windows\PFRO.log
2013-12-08 09:44 - 2013-12-08 09:44 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\AVAST Software
2013-12-07 21:34 - 2013-12-07 21:35 - 00049358 _____ C:\Users\Jeanette\Downloads\FRST.txt
2013-12-07 21:29 - 2013-12-07 21:29 - 00000186 _____ C:\Users\Jeanette\defogger_reenable
2013-12-07 18:43 - 2013-12-07 18:43 - 00000938 _____ C:\Users\Public\Desktop\Loaris Trojan Remover.lnk
2013-12-07 18:43 - 2013-12-07 18:43 - 00000000 ____D C:\Program Files\Loaris
2013-12-07 17:58 - 2013-12-07 18:01 - 00007512 _____ C:\Users\Jeanette\Downloads\SystemLook.txt
2013-12-07 17:57 - 2013-12-07 17:57 - 00165376 _____ C:\Users\Jeanette\Desktop\SystemLook_x64.exe
2013-12-07 17:40 - 2013-12-07 17:40 - 00000000 ____D C:\FRST
2013-12-07 17:39 - 2013-12-07 17:39 - 01927514 _____ (Farbar) C:\Users\Jeanette\Desktop\FRST64.exe
2013-12-07 17:32 - 2013-12-11 18:39 - 00001064 _____ C:\windows\setupact.log
2013-12-07 17:32 - 2013-12-07 17:32 - 00000000 _____ C:\windows\setuperr.log
2013-12-07 17:30 - 2013-12-07 17:30 - 00260376 _____ C:\Users\Jeanette\Documents\cc_20131207_173006.reg
2013-12-07 17:20 - 2013-12-07 17:20 - 00002778 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2013-12-07 17:16 - 2013-12-07 17:20 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-07 16:49 - 2013-12-08 19:26 - 00000000 ____D C:\AdwCleaner
2013-12-07 16:36 - 2013-12-07 16:37 - 01110034 _____ C:\Users\Jeanette\Desktop\AdwCleaner-3.014.exe
2013-12-07 15:32 - 2013-12-07 15:32 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\AVAST Software
2013-12-07 15:22 - 2013-12-07 15:22 - 00000192 _____ C:\windows\system32\Drivers\kgpfr2.cfg
2013-12-07 15:19 - 2013-12-10 19:09 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-12-07 15:19 - 2013-12-07 15:19 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-07 15:19 - 2013-12-07 15:19 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065264 _____ (AVAST Software) C:\windows\system32\Drivers\aswTdi.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-07 15:19 - 2013-12-07 15:19 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-12-07 15:18 - 2013-12-07 15:18 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-07 15:15 - 2013-12-07 15:15 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-07 15:01 - 2013-12-07 15:01 - 00001136 _____ C:\windows\system32\Drivers\kgpcpy.cfg
2013-12-07 15:01 - 2013-12-07 15:01 - 00000168 _____ C:\windows\SysWOW64\Drivers\kgpfr2.cfg
2013-12-07 15:00 - 2013-12-07 15:35 - 00000000 ____D C:\Program Files (x86)\STOPzilla!
2013-12-07 00:46 - 2013-12-07 09:25 - 00000000 ____D C:\Program Files (x86)\Re-markit
2013-12-07 00:01 - 2013-12-07 00:02 - 00000000 ____D C:\Users\Jeanette\Documents\Spannendes
2013-12-06 21:28 - 2013-12-06 21:44 - 628231075 _____ C:\Users\Jeanette\Downloads\LEGOMarvelDemo.zip
2013-12-06 21:19 - 2013-12-06 21:20 - 64790176 _____ (Rovio Entertainment Ltd.) C:\Users\Jeanette\Downloads\AngryBirdsRioInstaller_1.7.1.exe
2013-12-02 12:24 - 2013-12-02 12:25 - 36646912 _____ C:\Users\Jeanette\Downloads\ExtremeTuxRacer_0.6.0_x64.msi
2013-12-02 12:23 - 2013-12-02 12:23 - 01345613 _____ C:\Users\Jeanette\Downloads\Christmas_Font_Pack(2).zip
2013-12-01 09:59 - 2013-12-01 09:59 - 03891573 _____ C:\Users\Jeanette\Downloads\Freebie Lila-Lotta ZOO.zip
2013-11-27 19:23 - 2013-12-11 10:42 - 00000000 ____D C:\Users\Jeanette\Documents\Citavi 4
2013-11-27 18:22 - 2013-11-27 18:23 - 00000000 ____D C:\Program Files (x86)\Citavi 4
2013-11-27 15:09 - 2013-11-27 15:09 - 00003426 _____ C:\Users\Jeanette\Downloads\citavi-einstellungsdatei.csd
2013-11-27 10:51 - 2013-11-27 10:51 - 00107520 _____ C:\Users\Jeanette\Downloads\2013.11.17_G2-Adressen.xls
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\SZKG64.sys
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\is3srv64.sys
2013-11-18 21:57 - 2013-11-18 21:57 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Adobe_Systems_Incorporate
2013-11-18 21:56 - 2013-11-18 21:56 - 00002178 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
2013-11-18 19:17 - 2013-11-29 12:06 - 00015405 _____ C:\Users\Jeanette\Documents\Adressliste Katzengruppeteil 1.xlsx
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BLACKBERRY-47A9
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BlackBerry
2013-11-13 20:08 - 2013-11-13 20:08 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\XCPCSync.OEM
2013-11-13 20:07 - 2013-11-13 20:11 - 00000000 ____D C:\Users\Christoph\AppData\Local\Research In Motion
2013-11-13 20:07 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\Research In Motion
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00002225 _____ C:\Users\Public\Desktop\BlackBerry Link.lnk
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____D C:\ProgramData\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\out.txt
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\err.txt
2013-11-13 20:06 - 2012-12-10 15:48 - 00044544 _____ (Research in Motion Ltd) C:\windows\system32\Drivers\RimSerial_AMD64.sys
2013-11-13 20:05 - 2013-11-13 20:05 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2013-11-13 19:58 - 2013-11-13 19:58 - 13462360 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage(1).exe.part
2013-11-13 19:57 - 2013-11-13 20:01 - 164855312 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage.exe
2013-11-13 11:29 - 2013-11-13 11:29 - 00000000 ____D C:\windows\SysWOW64\20-20 Technologies
2013-11-12 14:35 - 2013-11-12 14:35 - 00000000 ____D C:\ProgramData\Oracle
2013-11-12 14:27 - 2013-11-12 14:26 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-12 10:59 - 2013-11-12 10:59 - 02594735 _____ C:\Users\Jeanette\Downloads\Fuchs-stundenplan.zip
2013-11-11 09:24 - 2013-12-11 15:37 - 00001887 _____ C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
==================== One Month Modified Files and Folders =======
2013-12-11 18:54 - 2013-12-11 18:54 - 00022197 _____ C:\Users\Jeanette\Desktop\FRST.txt
2013-12-11 18:53 - 2013-12-11 15:37 - 00001788 _____ C:\sc-cleaner.txt
2013-12-11 18:51 - 2012-04-06 18:41 - 00000884 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2013-12-11 18:47 - 2009-07-14 05:45 - 00013424 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-11 18:47 - 2009-07-14 05:45 - 00013424 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-11 18:41 - 2011-11-27 14:43 - 00000000 ____D C:\Users\Jeanette\Documents\Outlook-Dateien
2013-12-11 18:40 - 2013-12-09 16:03 - 00000000 ___RD C:\Users\Jeanette\Dropbox
2013-12-11 18:40 - 2013-12-09 15:59 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Dropbox
2013-12-11 18:39 - 2013-12-07 17:32 - 00001064 _____ C:\windows\setupact.log
2013-12-11 18:39 - 2012-04-01 12:03 - 00001110 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-12-11 18:39 - 2009-07-14 06:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2013-12-11 16:42 - 2011-05-17 16:16 - 01954234 _____ C:\windows\WindowsUpdate.log
2013-12-11 15:37 - 2013-11-11 09:24 - 00001887 _____ C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2013-12-11 15:28 - 2011-08-19 10:07 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-12-11 15:26 - 2013-07-16 21:55 - 00000000 ____D C:\windows\system32\MRT
2013-12-11 15:21 - 2011-06-08 20:03 - 90708896 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2013-12-11 15:19 - 2013-12-11 15:19 - 00406264 _____ (Bleeping Computer, LLC) C:\Users\Jeanette\Desktop\sc-cleaner.exe
2013-12-11 15:06 - 2012-04-01 12:03 - 00001114 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-12-11 11:02 - 2012-01-09 19:25 - 00000000 ____D C:\Users\Jeanette\Documents\Citavi 3
2013-12-11 10:42 - 2013-11-27 19:23 - 00000000 ____D C:\Users\Jeanette\Documents\Citavi 4
2013-12-11 10:14 - 2011-05-17 23:46 - 00698390 _____ C:\windows\system32\perfh007.dat
2013-12-11 10:14 - 2011-05-17 23:46 - 00149054 _____ C:\windows\system32\perfc007.dat
2013-12-11 10:14 - 2009-07-14 06:13 - 01617026 _____ C:\windows\system32\PerfStringBackup.INI
2013-12-10 20:52 - 2012-04-06 18:41 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2013-12-10 20:52 - 2012-04-06 18:41 - 00003822 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2013-12-10 20:52 - 2011-06-08 14:22 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-10 19:09 - 2013-12-07 15:19 - 00004182 _____ C:\windows\System32\Tasks\avast! Emergency Update
2013-12-10 19:07 - 2009-07-14 06:08 - 00032632 _____ C:\windows\Tasks\SCHEDLGU.TXT
2013-12-10 08:20 - 2013-12-08 15:22 - 00009166 _____ C:\windows\PFRO.log
2013-12-09 23:30 - 2013-12-09 23:30 - 00891184 _____ C:\Users\Jeanette\Desktop\SecurityCheck.exe
2013-12-09 20:04 - 2013-12-09 20:04 - 02347384 _____ (ESET) C:\Users\Jeanette\Desktop\esetsmartinstaller_enu.exe
2013-12-09 16:03 - 2011-06-05 09:16 - 00000000 ____D C:\Users\Jeanette
2013-12-09 16:01 - 2011-06-05 09:17 - 00000000 ___RD C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-12-09 16:00 - 2013-12-09 16:00 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2013-12-08 19:39 - 2013-12-08 19:39 - 00000000 ____D C:\windows\ERUNT
2013-12-08 19:26 - 2013-12-07 16:49 - 00000000 ____D C:\AdwCleaner
2013-12-08 18:55 - 2013-12-08 18:55 - 00001109 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-12-08 18:55 - 2013-12-08 18:55 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-12-08 18:53 - 2013-12-08 18:53 - 01034531 _____ (Thisisu) C:\Users\Jeanette\Desktop\JRT.exe
2013-12-08 16:05 - 2013-12-08 16:05 - 04286464 _____ C:\Users\Jeanette\Downloads\anyconnect-win-3.1.04059-pre-deploy-k9.msi
2013-12-08 15:20 - 2009-07-14 03:34 - 00000478 _____ C:\windows\win.ini
2013-12-08 09:44 - 2013-12-08 09:44 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\AVAST Software
2013-12-07 21:35 - 2013-12-07 21:34 - 00049358 _____ C:\Users\Jeanette\Downloads\FRST.txt
2013-12-07 21:29 - 2013-12-07 21:29 - 00000186 _____ C:\Users\Jeanette\defogger_reenable
2013-12-07 20:09 - 2012-06-22 08:41 - 00000000 ____D C:\Program Files (x86)\Bonjour
2013-12-07 18:43 - 2013-12-07 18:43 - 00000938 _____ C:\Users\Public\Desktop\Loaris Trojan Remover.lnk
2013-12-07 18:43 - 2013-12-07 18:43 - 00000000 ____D C:\Program Files\Loaris
2013-12-07 18:01 - 2013-12-07 17:58 - 00007512 _____ C:\Users\Jeanette\Downloads\SystemLook.txt
2013-12-07 17:57 - 2013-12-07 17:57 - 00165376 _____ C:\Users\Jeanette\Desktop\SystemLook_x64.exe
2013-12-07 17:40 - 2013-12-07 17:40 - 00000000 ____D C:\FRST
2013-12-07 17:39 - 2013-12-07 17:39 - 01927514 _____ (Farbar) C:\Users\Jeanette\Desktop\FRST64.exe
2013-12-07 17:32 - 2013-12-07 17:32 - 00000000 _____ C:\windows\setuperr.log
2013-12-07 17:30 - 2013-12-07 17:30 - 00260376 _____ C:\Users\Jeanette\Documents\cc_20131207_173006.reg
2013-12-07 17:20 - 2013-12-07 17:20 - 00002778 _____ C:\windows\System32\Tasks\CCleanerSkipUAC
2013-12-07 17:20 - 2013-12-07 17:16 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-12-07 17:20 - 2012-04-17 10:58 - 00000000 ____D C:\Program Files\CCleaner
2013-12-07 16:39 - 2011-06-08 13:40 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Adobe
2013-12-07 16:37 - 2013-12-07 16:36 - 01110034 _____ C:\Users\Jeanette\Desktop\AdwCleaner-3.014.exe
2013-12-07 16:06 - 2011-06-06 11:19 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Simple Sudoku
2013-12-07 15:35 - 2013-12-07 15:00 - 00000000 ____D C:\Program Files (x86)\STOPzilla!
2013-12-07 15:32 - 2013-12-07 15:32 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\AVAST Software
2013-12-07 15:22 - 2013-12-07 15:22 - 00000192 _____ C:\windows\system32\Drivers\kgpfr2.cfg
2013-12-07 15:19 - 2013-12-07 15:19 - 01032416 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00409832 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00334648 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2013-12-07 15:19 - 2013-12-07 15:19 - 00205320 _____ C:\windows\system32\Drivers\aswVmm.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00092544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00084328 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065776 _____ C:\windows\system32\Drivers\aswRvrt.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00065264 _____ (AVAST Software) C:\windows\system32\Drivers\aswTdi.sys
2013-12-07 15:19 - 2013-12-07 15:19 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2013-12-07 15:19 - 2013-12-07 15:19 - 00038984 _____ (AVAST Software) C:\windows\system32\Drivers\aswFsBlk.sys
2013-12-07 15:18 - 2013-12-07 15:18 - 00000000 ____D C:\Program Files\AVAST Software
2013-12-07 15:15 - 2013-12-07 15:15 - 00000000 ____D C:\ProgramData\AVAST Software
2013-12-07 15:10 - 2011-09-18 14:01 - 00000000 ____D C:\windows\Minidump
2013-12-07 15:01 - 2013-12-07 15:01 - 00001136 _____ C:\windows\system32\Drivers\kgpcpy.cfg
2013-12-07 15:01 - 2013-12-07 15:01 - 00000168 _____ C:\windows\SysWOW64\Drivers\kgpfr2.cfg
2013-12-07 09:25 - 2013-12-07 00:46 - 00000000 ____D C:\Program Files (x86)\Re-markit
2013-12-07 00:02 - 2013-12-07 00:01 - 00000000 ____D C:\Users\Jeanette\Documents\Spannendes
2013-12-06 21:44 - 2013-12-06 21:28 - 628231075 _____ C:\Users\Jeanette\Downloads\LEGOMarvelDemo.zip
2013-12-06 21:20 - 2013-12-06 21:19 - 64790176 _____ (Rovio Entertainment Ltd.) C:\Users\Jeanette\Downloads\AngryBirdsRioInstaller_1.7.1.exe
2013-12-06 20:56 - 2011-06-15 09:44 - 00000000 ____D C:\Users\Jeanette\Documents\Nähen
2013-12-04 20:01 - 2012-04-01 12:03 - 00004110 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-12-04 20:01 - 2012-04-01 12:03 - 00003858 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-12-02 12:25 - 2013-12-02 12:24 - 36646912 _____ C:\Users\Jeanette\Downloads\ExtremeTuxRacer_0.6.0_x64.msi
2013-12-02 12:23 - 2013-12-02 12:23 - 01345613 _____ C:\Users\Jeanette\Downloads\Christmas_Font_Pack(2).zip
2013-12-01 09:59 - 2013-12-01 09:59 - 03891573 _____ C:\Users\Jeanette\Downloads\Freebie Lila-Lotta ZOO.zip
2013-11-29 12:06 - 2013-11-18 19:17 - 00015405 _____ C:\Users\Jeanette\Documents\Adressliste Katzengruppeteil 1.xlsx
2013-11-27 20:24 - 2012-01-09 19:25 - 00000000 ____D C:\Users\Jeanette\AppData\Roaming\Swiss Academic Software
2013-11-27 19:24 - 2011-11-03 21:12 - 00000000 ____D C:\Users\Jeanette\Documents\Hannspad Backup
2013-11-27 19:19 - 2013-01-20 19:16 - 00000000 ____D C:\Users\Jeanette\Documents\Martinsverein
2013-11-27 18:26 - 2011-10-22 18:17 - 00000000 ____D C:\Users\Jeanette\AppData\Local\MediaMonkey
2013-11-27 18:26 - 2011-10-22 18:17 - 00000000 ____D C:\Program Files (x86)\MediaMonkey
2013-11-27 18:24 - 2012-01-09 19:12 - 00000000 ____D C:\ProgramData\Swiss Academic Software
2013-11-27 18:23 - 2013-11-27 18:22 - 00000000 ____D C:\Program Files (x86)\Citavi 4
2013-11-27 18:20 - 2011-09-10 11:23 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Downloaded Installations
2013-11-27 15:33 - 2011-06-06 09:18 - 00000000 ____D C:\Users\Jeanette\Documents\Youcam
2013-11-27 15:15 - 2012-07-07 08:41 - 01591306 _____ C:\windows\SysWOW64\PerfStringBackup.INI
2013-11-27 15:09 - 2013-11-27 15:09 - 00003426 _____ C:\Users\Jeanette\Downloads\citavi-einstellungsdatei.csd
2013-11-27 10:51 - 2013-11-27 10:51 - 00107520 _____ C:\Users\Jeanette\Downloads\2013.11.17_G2-Adressen.xls
2013-11-21 08:26 - 2012-08-28 09:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-11-20 20:56 - 2011-06-06 09:53 - 00000000 ____D C:\Program Files (x86)\Internet
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\SZKG64.sys
2013-11-19 14:15 - 2013-11-19 14:15 - 00074768 ____R (iS3 Inc.) C:\windows\SysWOW64\Drivers\is3srv64.sys
2013-11-19 03:33 - 2011-06-05 12:42 - 00267936 ____N (Microsoft Corporation) C:\windows\system32\MpSigStub.exe
2013-11-18 21:57 - 2013-11-18 21:57 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Adobe_Systems_Incorporate
2013-11-18 21:57 - 2011-11-27 10:44 - 00000000 ____D C:\Users\Jeanette\Documents\My Digital Editions
2013-11-18 21:56 - 2013-11-18 21:56 - 00002178 _____ C:\Users\Public\Desktop\Adobe Digital Editions 2.0.lnk
2013-11-18 21:56 - 2011-08-05 21:35 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-11-18 21:52 - 2012-04-03 21:57 - 00000000 ____D C:\Program Files (x86)\Purplehills
2013-11-18 19:21 - 2011-12-01 10:26 - 00000000 ____D C:\Users\Jeanette\Documents\schule
2013-11-18 17:15 - 2012-10-05 11:01 - 00000000 ____D C:\Users\Jeanette\Documents\Kita
2013-11-14 20:06 - 2011-10-15 13:52 - 00000000 ____D C:\Users\Christoph\AppData\Local\Microsoft Help
2013-11-13 20:11 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Christoph\AppData\Local\Research In Motion
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BLACKBERRY-47A9
2013-11-13 20:10 - 2013-11-13 20:10 - 00000000 ____D C:\Users\Christoph\Documents\BlackBerry
2013-11-13 20:10 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\Research In Motion
2013-11-13 20:08 - 2013-11-13 20:08 - 00000000 ____D C:\Users\Christoph\AppData\Roaming\XCPCSync.OEM
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimUsb_AMD64_01007.Wdf
2013-11-13 20:07 - 2013-11-13 20:07 - 00000000 ____D C:\Users\Jeanette\AppData\Local\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00002225 _____ C:\Users\Public\Desktop\BlackBerry Link.lnk
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____H C:\windows\system32\Drivers\Msft_Kernel_RimSerial_AMD64_01007.Wdf
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 ____D C:\ProgramData\Research In Motion
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\out.txt
2013-11-13 20:06 - 2013-11-13 20:06 - 00000000 _____ C:\windows\SysWOW64\err.txt
2013-11-13 20:05 - 2013-11-13 20:05 - 00000000 ____D C:\Program Files (x86)\Research In Motion
2013-11-13 20:01 - 2013-11-13 19:57 - 164855312 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage.exe
2013-11-13 19:58 - 2013-11-13 19:58 - 13462360 _____ C:\Users\Christoph\Downloads\121_b023_multilanguage(1).exe.part
2013-11-13 11:29 - 2013-11-13 11:29 - 00000000 ____D C:\windows\SysWOW64\20-20 Technologies
2013-11-13 11:20 - 2013-10-07 12:18 - 00012086 _____ C:\Users\Jeanette\Documents\Adressvorlage neu.xlsx
2013-11-12 14:35 - 2013-11-12 14:35 - 00000000 ____D C:\ProgramData\Oracle
2013-11-12 14:26 - 2013-11-12 14:27 - 00264616 _____ (Oracle Corporation) C:\windows\SysWOW64\javaws.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00175016 _____ (Oracle Corporation) C:\windows\SysWOW64\javaw.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00174504 _____ (Oracle Corporation) C:\windows\SysWOW64\java.exe
2013-11-12 14:26 - 2013-11-12 14:26 - 00096168 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2013-11-12 14:26 - 2011-06-06 11:20 - 00000000 ____D C:\Program Files (x86)\Java
2013-11-12 10:59 - 2013-11-12 10:59 - 02594735 _____ C:\Users\Jeanette\Downloads\Fuchs-stundenplan.zip
Some content of TEMP:
====================
C:\Users\Christoph\AppData\Local\Temp\avgnt.exe
C:\Users\Christoph\AppData\Local\Temp\BlackBerryDeviceManager.exe
C:\Users\Christoph\AppData\Local\Temp\BlackBerryLauncher.exe
C:\Users\Christoph\AppData\Local\Temp\FileSystemView.dll
C:\Users\Jeanette\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-12-11 15:06
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
War es das jetzt?
Schönen Abend,
ennachen |