prichert | 29.06.2014 22:14 | Hallo "schrauber",
vielen Dank für die schnelle Antwort und die Info.
Hier die log-files:
MBAM: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 29.06.2014
Suchlauf-Zeit: 22:32:13
Logdatei: MBAM.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.29.08
Rootkit Datenbank: v2014.06.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x86
Dateisystem: NTFS
Benutzer: Richerts
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 260864
Verstrichene Zeit: 12 Min, 4 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 0
(No malicious items detected)
Registrierungsdaten: 6
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_O1WDQhweL4bkM_JB5F8cVCzohr6E23-AS_dtzlDJkcb1SHv6DKmXUilFqQOMhzj, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_O1WDQhweL4bkM_JB5F8cVCzohr6E23-AS_dtzlDJkcb1SHv6DKmXUilFqQOMhzj),Ersetzt,[62da05799cdfba7cc934ddad4aba29d7]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Bar, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}),Ersetzt,[8eaea7d70d6e5adc40bb7317b3511ee2]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}),Ersetzt,[d26a740aaccf3cfafc002268ad57a45c]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}),Ersetzt,[0c30c1bda6d543f34db1a9e18d77f808]
PUP.Optional.Snapdo, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}, Gut: (hxxp://www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}),Ersetzt,[4fedf589116ad16597688a00c044ca36]
PUP.Optional.SnapDo.A, HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?p=mKO_AwFzXIpYRbPAMW02fQbYPFkTjj8jzRyB0rQvzyej3yvtCjyXXnQme9oxsQRSyyp0BtpJcuZo7U6IVqMMW0uEYoX7FDkM0V0R46ALT9cb8HUXi6ho4p41ABQxmQ34IwJu_OGLqNTIAMoSqjAKr5ftKI4vRXclw8mMxqK3iyjs1OKzBR57Ljn9CttDopRuGU3V&q={searchTerms}),Ersetzt,[023a2955314afa3cc6d1d4ad4aba2ad6]
Ordner: 14
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\lib, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\de, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\en, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\es, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\fr, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\it, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\pl, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\ru, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
Dateien: 29
PUP.Optional.Spigot.A, C:\Windows\Installer\359ce500.msi, In Quarantäne, [ae8e1e6080fb74c28fbcabdc976aa15f],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\background.html, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\ciuvo.min.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\contentscript.min.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\manifest.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\options.html, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\options.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src\connected_page.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src\csl.min.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src\grinder_base.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src\interpreter.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src\plugins.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src\templates.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\base-src\toolbar.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo\ciuvo_active.png, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo\ciuvo_active_small.png, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo\ciuvo_icon.png, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo\ciuvo_inactive.png, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo\ciuvo_inactive_small.png, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo\ciuvo_star.png, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\icons\ciuvo\ciuvo_star_small.png, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\lib\Jtl_1.0-pre.js, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\de\messages.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\en\messages.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\es\messages.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\fr\messages.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\it\messages.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\pl\messages.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
PUP.Optional.Ciuvo.A, C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbmmkkbjmcidpennbibfkncodjenfpjh\1.4.17_0\_locales\ru\messages.json, In Quarantäne, [023ae49acead76c0d9ae456748ba58a8],
Physische Sektoren: 0
(No malicious items detected)
(end) AdwCleaner Code:
# AdwCleaner v3.213 - Bericht erstellt am 29/06/2014 um 22:55:04
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits)
# Benutzername : Richerts - RICHERTS-PC
# Gestartet von : C:\Users\Richerts\Downloads\adwcleaner_3.213.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\GreenTree Applications
Ordner Gelöscht : C:\Users\Richerts\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Richerts\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\ScriptHost.Tool.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BackupStack_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\LatestDLMgr_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{19D2F415-D58B-46BC-9390-C03DCBC21EB2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6E45F3E8-2683-4824-A6BE-08108022FB36}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{9F0F16DD-4E76-4049-A9B1-7A91E48F0323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{F4288797-CB12-49CE-9DF8-7CDFA1143BEA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{212C2C4F-C845-4FBC-9561-C833A13D8DCE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{3C5D1D57-16C8-473C-A552-37B8D88596FE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4A115D8A-6A7B-4C72-92B1-2E2D01F36979}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{99DF8440-814E-497F-BDDD-FB93E9E9DF96}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{83CAD530-387D-40FD-82EA-B9E863D92A9B}
Schlüssel Gelöscht : HKCU\Software\OCS
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Mozilla Firefox v26.0 (de)
[ Datei : C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\Profiles\0\prefs.js ]
[ Datei : C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\Profiles\2sa4jryb.default\prefs.js ]
[ Datei : C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\Profiles\extensions\prefs.js ]
[ Datei : C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\Profiles\y56f4fpv.default\prefs.js ]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : pdnkcidphdcakpkheohlhocaicfamjie
*************************
AdwCleaner[R0].txt - [15329 octets] - [17/12/2013 22:59:32]
AdwCleaner[R1].txt - [8393 octets] - [27/04/2014 21:32:31]
AdwCleaner[R2].txt - [3900 octets] - [29/06/2014 22:52:15]
AdwCleaner[S0].txt - [15246 octets] - [17/12/2013 23:05:20]
AdwCleaner[S1].txt - [6846 octets] - [27/04/2014 22:13:29]
AdwCleaner[S2].txt - [3825 octets] - [29/06/2014 22:55:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3885 octets] ########## Junkware Removal Tool Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x86
Ran by Richerts on 29.06.2014 at 23:01:21,96
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2263252255-1708856640-2164245826-1000\Software\sweetim
~~~ Files
Successfully deleted: [File] C:\Windows\system32\RENAD5F.tmp
Successfully deleted: [File] C:\Windows\system32\RENAD60.tmp
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\cloud software ltd"
Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader"
~~~ FireFox
Successfully deleted: [Folder] C:\Users\Richerts\AppData\Roaming\mozilla\firefox\profiles\2sa4jryb.default\extensions\staged
Failed to delete: [Folder] C:\Users\Richerts\AppData\Roaming\mozilla\firefox\profiles\2sa4jryb.default\extensions\ytd@mybrowserbar.com
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 29.06.2014 at 23:05:27,31
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ neues FRST-Log
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:28-06-2014 02
Ran by Richerts (administrator) on RICHERTS-PC on 29-06-2014 23:07:45
Running from C:\Users\Richerts\Downloads
Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Ellora Assets Corp.) C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
() C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe
(SAMSUNG Electronics) C:\Program Files\Samsung\Samsung Support Center\SSCKbdHk.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Google) C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
() C:\Program Files\Canon\IJPLM\ijplmsvc.exe
(BUFFALO INC.) C:\Program Files\BUFFALO\NASNAVI\nassvc.exe
(pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe
(Buffalo Inc.) C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(BUFFALO INC.) C:\Program Files\BUFFALO\NASNAVI\nassche.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1713448 2010-02-26] (Synaptics Incorporated)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-12] (Apple Inc.)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [3825176 2012-11-13] (Safer-Networking Ltd.)
HKLM\...\Run: [KeePass 2 PreLoad] => C:\Program Files\KeePass Password Safe 2\KeePass.exe [2099200 2014-04-13] (Dominik Reichl)
HKLM\...\Run: [CanonSolutionMenuEx] => C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE [1637528 2012-10-09] (CANON INC.)
HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24Creator\pdf24.exe [162856 2013-07-22] (Geek Software GmbH)
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2565520 2011-03-14] (CANON INC.)
HKLM\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452016 2011-01-15] (CANON INC.)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [ZoneAlarm] => C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [137352 2014-05-30] (Check Point Software Technologies Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-2263252255-1708856640-2164245826-1000\...\Run: [OfficeSyncProcess] => C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-2263252255-1708856640-2164245826-1000\...\Run: [] => C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [843568 2014-05-28] (Samsung)
HKU\S-1-5-21-2263252255-1708856640-2164245826-1000\...\Run: [KiesAirMessage] => C:\Program Files\Samsung\Kies\KiesAirMessage.exe [578560 2013-03-20] (Samsung Electronics)
HKU\S-1-5-21-2263252255-1708856640-2164245826-1000\...\Run: [KiesPreload] => C:\Program Files\Samsung\Kies\Kies.exe [1563440 2014-05-28] (Samsung)
HKU\S-1-5-21-2263252255-1708856640-2164245826-1000\...\Run: [Spybot-S&D Cleaning] => C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe [3713032 2012-11-13] (Safer-Networking Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Google Calendar Sync.lnk
ShortcutTarget: Google Calendar Sync.lnk -> C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe (Google)
Startup: C:\Users\Richerts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BUFFALO NAS Navigator2.lnk
ShortcutTarget: BUFFALO NAS Navigator2.lnk -> C:\Program Files\BUFFALO\NASNAVI\NasNavi.exe (Buffalo Inc.)
Startup: C:\Users\Richerts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft SharePoint Workspace.lnk
ShortcutTarget: Microsoft SharePoint Workspace.lnk -> C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
Startup: C:\Users\Richerts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\NAS Scheduler.lnk
ShortcutTarget: NAS Scheduler.lnk -> C:\Program Files\BUFFALO\NASNAVI\nassche.exe (BUFFALO INC.)
Startup: C:\Users\Richerts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 1 (GFS Unread Stub) -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 2 (GFS Stub) -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 3 (GFS Folder) -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 4 (GFS Unread Mark) -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://de.search.yahoo.com/?type=501549&fr=spigot-yhp-ie
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8D34185D0C35CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {FB442BEF-A6F0-4316-8168-EC3575B2A5C2} URL = https://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=501549&p={searchTerms}
BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\Profiles\2sa4jryb.default
FF DefaultSearchEngine: Yahoo!
FF SelectedSearchEngine: Yahoo!
FF Keyword.URL: https://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=501549&p=
FF Homepage: https://de.search.yahoo.com/?type=501549&fr=spigot-yhp-ff
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin: @java.com/DTPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
FF SearchPlugin: C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\Profiles\2sa4jryb.default\searchplugins\yahoo_ff.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\profiles\extensions\extensions [2014-03-26]
FF Extension: No Name - C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\profiles\extensions\searchplugins [2014-03-26]
FF Extension: HDvid Codec - C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\profiles\extensions\hdvc@hdvc.com.xpi [2013-04-17]
FF Extension: Snap.Do - C:\Users\Richerts\AppData\Roaming\Mozilla\Firefox\Profiles\2sa4jryb.default\Extensions\{f9fc93be-f796-7006-7b62-402a556f07a7} [2014-03-26]
FF HKLM\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files\PDF Architect\FFPDFArchitectExt [2013-01-07]
FF HKLM\...\Firefox\Extensions: [fmdownloader@gmail.com] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF Extension: Freemake Video Downloader Plugin - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com [2014-01-15]
FF HKLM\...\Firefox\Extensions: [ytfmdownloader@gmail.com] - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
FF Extension: Freemake Youtube Download Button - C:\Program Files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com [2014-01-15]
Chrome:
=======
CHR HomePage: https://www.google.de/
CHR StartupUrls: "https://www.google.de/"
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.153\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (AmazonMP3DownloaderPlugin) - C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101721.dll (Amazon.com, Inc.)
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U21) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
CHR Extension: (Google Drive) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-04-29]
CHR Extension: (WOT) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2013-04-29]
CHR Extension: (YouTube) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-04-29]
CHR Extension: (Adblock Plus) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2013-04-29]
CHR Extension: (Google-Suche) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-04-29]
CHR Extension: (Readium) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\fepbnnnkkadjhjahcafoaglimekefifl [2014-05-30]
CHR Extension: (3D-Bowling) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\gemohgpikgjbgmdfbfjdailocichgbjm [2013-04-29]
CHR Extension: (ZoneAlarm Chrome Toolbar) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgdcapepedmpopjkmdbjnmmmfgllnfek [2014-06-22]
CHR Extension: (LearningApps.org) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkpajokdkoidfiohkeknhhheinfpimfc [2014-03-31]
CHR Extension: (World Data Atlas) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\knlgfedckdhkgjinnhogmhkbcjpmmhko [2014-03-31]
CHR Extension: (WorkFlowy) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\koegeopamaoljbmhnfjbclbocehhgmkm [2014-03-31]
CHR Extension: (Google Wallet) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR Extension: (Google Mail) - C:\Users\Richerts\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-04-29]
CHR HKCU\...\Chrome\Extension: [kgdcapepedmpopjkmdbjnmmmfgllnfek] - C:\Users\Richerts\AppData\Roaming\Check Point Software Technologies LTD\zonealarm\1.8.29.17\zonealarm.crx [2014-02-12]
========================== Services (Whitelisted) =================
R2 AAV UpdateService; C:\Program Files\Akademische Arbeitsgemeinschaft\AAVUpdateManager\aavus.exe [128296 2008-10-24] ()
S3 becldr3Service; C:\Program Files\BCL Technologies\easyConverter SDK 3\Common\becldr.exe [176128 2011-04-19] () [File not signed]
R2 FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [9216 2014-01-13] (Ellora Assets Corp.) [File not signed]
R2 FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [233472 2013-02-05] (Teruten) [File not signed]
R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [138192 2011-02-07] ()
R2 NasPmService; C:\Program Files\BUFFALO\NASNAVI\nassvc.exe [251760 2014-01-05] (BUFFALO INC.)
S3 OpenVPNService; C:\Program Files\OpenVPN\bin\openvpnserv.exe [32568 2014-05-02] (The OpenVPN Project)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1522312 2012-11-22] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [905864 2012-11-22] (pdfforge GbR)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3592120 2014-05-30] (Check Point Software Technologies Ltd.)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [90936 2014-05-29] (Check Point Software Technologies, Ltd.)
==================== Drivers (Whitelisted) ====================
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-02-05] () [File not signed]
R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2014-04-30] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [488032 2014-04-30] (Kaspersky Lab ZAO)
S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [15688 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [10320 2013-09-30] ()
R3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [35288 2013-08-22] (The OpenVPN Project)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [456088 2014-05-30] (Check Point Software Technologies Ltd.)
R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] ()
S3 IntcAzAudAddService; system32\drivers\RTKVHDA.sys [X]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [74848 2014-04-30] (Kaspersky Lab ZAO)
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 NPF; system32\drivers\NPF.sys [X]
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-29 23:05 - 2014-06-29 23:05 - 00001475 _____ () C:\Users\Richerts\Desktop\JRT.txt
2014-06-29 23:01 - 2014-06-29 23:01 - 00000000 ____D () C:\Windows\ERUNT
2014-06-29 23:00 - 2014-06-29 23:01 - 01016261 _____ (Thisisu) C:\Users\Richerts\Downloads\JRT.exe
2014-06-29 22:50 - 2014-06-29 22:51 - 01342659 _____ () C:\Users\Richerts\Downloads\adwcleaner_3.213.exe
2014-06-29 22:30 - 2014-06-29 22:31 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 22:30 - 2014-06-29 22:30 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-29 22:30 - 2014-06-29 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-29 22:30 - 2014-06-29 22:30 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-29 22:30 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-06-29 22:30 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-06-29 22:30 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-06-29 22:27 - 2014-06-29 22:28 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Richerts\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-29 22:04 - 2014-06-29 22:04 - 00001226 _____ () C:\Users\Richerts\Desktop\Revo Uninstaller.lnk
2014-06-29 22:04 - 2014-06-29 22:04 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-29 22:03 - 2014-06-29 22:04 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Richerts\Downloads\revosetup95.exe
2014-06-29 20:57 - 2014-06-29 20:57 - 00003296 _____ () C:\Users\Richerts\Downloads\Gmer.txt.txt.zip
2014-06-29 20:52 - 2014-06-29 20:52 - 01110476 _____ () C:\Users\Richerts\Downloads\7z920.exe
2014-06-29 20:52 - 2014-06-29 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-06-29 20:52 - 2014-06-29 20:52 - 00000000 ____D () C:\Program Files\7-Zip
2014-06-29 20:14 - 2014-06-29 20:14 - 00380416 _____ () C:\Users\Richerts\Downloads\Gmer-19357.exe
2014-06-29 20:12 - 2014-06-29 23:06 - 00000000 ____D () C:\Users\Richerts\Desktop\Trojaner Board
2014-06-29 20:12 - 2014-06-29 20:13 - 00033909 _____ () C:\Users\Richerts\Downloads\Addition.txt
2014-06-29 20:11 - 2014-06-29 23:07 - 00022116 _____ () C:\Users\Richerts\Downloads\FRST.txt
2014-06-29 20:11 - 2014-06-29 23:07 - 00000000 ____D () C:\FRST
2014-06-29 20:10 - 2014-06-29 20:11 - 01073664 _____ (Farbar) C:\Users\Richerts\Downloads\FRST.exe
2014-06-29 20:09 - 2014-06-29 20:09 - 00000478 _____ () C:\Users\Richerts\Downloads\defogger_disable.log
2014-06-29 20:09 - 2014-06-29 20:09 - 00000000 _____ () C:\Users\Richerts\defogger_reenable
2014-06-29 20:08 - 2014-06-29 20:08 - 00050477 _____ () C:\Users\Richerts\Downloads\Defogger.exe
2014-06-29 19:14 - 2014-06-29 19:16 - 00104960 _____ () C:\Users\Richerts\Desktop\Lied zum Abschied Kl 4a Rischenau.pub
2014-06-29 19:11 - 2014-06-29 19:14 - 00097792 _____ () C:\Users\Richerts\Downloads\Lied zum Abschied.pub
2014-06-26 21:09 - 2014-06-26 21:09 - 154764088 _____ () C:\Users\Richerts\Documents\Amazing Modern Dancing Airport Flashmob 2014.mp4
2014-06-23 22:51 - 2014-06-23 22:51 - 00023843 _____ () C:\Users\Richerts\Downloads\UR_Entwurf_ Napoleon _ Kaiser der Franzosen.zip
2014-06-23 22:28 - 2014-06-23 22:50 - 07610880 _____ () C:\Users\Richerts\Downloads\Napoleon Bonaparte.ppt
2014-06-23 16:25 - 2014-06-23 16:25 - 00868352 _____ () C:\Users\Richerts\Downloads\206.ppt
2014-06-23 16:24 - 2014-06-23 16:24 - 01362944 _____ () C:\Users\Richerts\Downloads\202.ppt
2014-06-23 16:23 - 2014-06-23 16:23 - 00338432 _____ () C:\Users\Richerts\Downloads\195.ppt
2014-06-23 16:23 - 2014-06-23 16:23 - 00104960 _____ () C:\Users\Richerts\Downloads\197.ppt
2014-06-23 16:21 - 2014-06-23 16:21 - 00582144 _____ () C:\Users\Richerts\Downloads\193.ppt
2014-06-23 16:18 - 2014-06-23 16:18 - 00384512 _____ () C:\Users\Richerts\Downloads\199.ppt
2014-06-22 23:19 - 2014-03-31 09:35 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-06-22 23:15 - 2014-06-28 00:01 - 00008969 ____H () C:\Windows\system32\BTImages.dat
2014-06-22 22:52 - 2014-06-22 22:52 - 00431135 _____ () C:\Windows\system32\Drivers\vsconfig.xml
2014-06-22 22:52 - 2014-04-30 11:01 - 00488032 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-06-22 22:52 - 2014-04-30 11:01 - 00074848 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-06-22 22:52 - 2014-04-30 11:00 - 00135776 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2014-06-22 22:51 - 2014-06-22 22:51 - 00000732 _____ () C:\Users\Public\Desktop\ZoneAlarm Security.lnk
2014-06-22 22:51 - 2014-06-22 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
2014-06-22 22:48 - 2014-06-22 22:48 - 03394856 _____ (Check Point Software Technologies Ltd.) C:\Users\Richerts\Downloads\zaSetupWeb_132_015_000 (1).exe
2014-06-22 22:47 - 2014-06-22 22:51 - 00000000 ____D () C:\Program Files\CheckPoint
2014-06-22 22:47 - 2014-06-22 22:47 - 03394856 _____ (Check Point Software Technologies Ltd.) C:\Users\Richerts\Downloads\zaSetupWeb_132_015_000.exe
2014-06-22 22:47 - 2014-06-22 22:47 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\Check Point Software Technologies LTD
2014-06-22 22:47 - 2014-06-22 22:47 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-06-22 22:47 - 2014-06-22 22:47 - 00000000 ____D () C:\Program Files\Check Point Software Technologies LTD
2014-06-22 22:21 - 2014-06-22 22:22 - 00000000 ____D () C:\Users\Richerts\Desktop\Wir sind die Maus Wave Datei
2014-06-22 22:19 - 2014-06-22 22:19 - 00002178 _____ () C:\Users\Public\Desktop\Free Audio Converter.lnk
2014-06-22 22:17 - 2014-06-22 22:17 - 34314288 _____ (DVDVideoSoft Ltd. ) C:\Users\Richerts\Downloads\FreeAudioConverter5.0.43.605.exe
2014-06-22 22:07 - 2014-06-26 21:06 - 00000000 ____D () C:\Users\Richerts\Desktop\Videos 8c
2014-06-22 21:19 - 2014-06-22 21:19 - 00810950 _____ () C:\Users\Richerts\Downloads\sprachgeschichte_offen.zip
2014-06-22 18:01 - 2014-06-22 18:01 - 142293945 _____ () C:\Users\Richerts\Desktop\Die großen Entdecker der Welt_ Cook, Kolumbus, Vespucci, ect..mp4
2014-06-22 17:55 - 2014-06-22 17:55 - 165446210 _____ () C:\Users\Richerts\Desktop\DOKU_Christoph Kolumbus - Die Wahre Biografie_DEUTSCH _ 2014.mp4
2014-06-22 17:42 - 2014-06-22 17:42 - 00001251 _____ () C:\Users\Public\Desktop\YTD Video Downloader.lnk
2014-06-22 17:41 - 2014-06-22 17:41 - 11227432 _____ () C:\Users\Richerts\Downloads\YTDSetup481.exe
2014-06-12 10:19 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-12 10:19 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-12 10:19 - 2014-05-30 11:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-12 10:19 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-12 10:19 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-12 10:19 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-12 10:19 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-12 10:19 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-12 10:19 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-12 10:19 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-12 10:19 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-12 10:19 - 2014-05-30 10:28 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-12 10:19 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-12 10:19 - 2014-05-30 10:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-12 10:19 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-12 10:19 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-12 10:19 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-12 10:19 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-12 10:19 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-12 10:19 - 2014-05-30 09:57 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-12 10:19 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-12 10:19 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-12 10:19 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-12 10:19 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-12 10:19 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-12 10:19 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-12 10:19 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-12 10:19 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-12 10:18 - 2014-06-08 10:48 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 10:18 - 2014-06-08 10:43 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-12 10:18 - 2014-04-05 04:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 10:18 - 2014-04-05 04:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 10:18 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 10:18 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 10:18 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 10:18 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 10:17 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 10:08 - 2014-06-29 22:56 - 00018566 _____ () C:\Windows\PFRO.log
2014-06-12 10:08 - 2014-06-29 22:56 - 00001133 _____ () C:\Windows\setupact.log
2014-06-12 10:08 - 2014-06-12 10:08 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-11 09:37 - 2014-05-08 11:06 - 02742784 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-11 09:37 - 2014-05-08 11:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-09 13:32 - 2014-06-09 13:32 - 00015872 _____ () C:\Users\Richerts\Downloads\Rueckmeldebogen Schuelerverhalten_positive Verstaerkung.xls
2014-06-03 20:45 - 2014-06-03 20:45 - 00691572 _____ () C:\Users\Richerts\Downloads\kommunikation.hlp
2014-06-03 20:22 - 2014-06-12 13:52 - 00000000 ____D () C:\Users\Richerts\Desktop\UPPs
2014-06-03 17:53 - 2014-06-03 17:53 - 00000000 ____D () C:\Users\Richerts\AppData\Local\PDFCreator
2014-06-02 19:00 - 2014-06-02 19:00 - 00417416 _____ () C:\Users\Richerts\Downloads\diversevorlagen.zip
2014-06-02 16:53 - 2014-06-02 16:53 - 13525781 _____ () C:\Users\Richerts\Downloads\tesseract-ocr-setup-3.02.02.exe
2014-06-02 16:50 - 2014-06-05 17:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-06-02 16:50 - 2014-06-02 16:50 - 00000000 ____D () C:\Program Files\PDFCreator
2014-06-02 16:50 - 2014-04-17 19:36 - 00095928 _____ (pdfforge GmbH) C:\Windows\system32\pdfcmon.dll
2014-06-02 16:49 - 2014-06-02 16:50 - 01825064 _____ () C:\Users\Richerts\Downloads\tesseract-ocr-3.02.deu.tar.gz
2014-06-02 10:44 - 2014-06-02 10:44 - 25055960 _____ (pdfforge ) C:\Users\Richerts\Downloads\PDFCreator-1_9_3-setup.exe
2014-06-01 22:29 - 2014-06-01 22:29 - 00045541 _____ () C:\Users\Richerts\Downloads\marseillaise_military.mid
2014-06-01 22:28 - 2014-06-01 22:28 - 00007107 _____ () C:\Users\Richerts\Downloads\marseillaise.mid
2014-06-01 22:09 - 2014-06-01 22:09 - 03238941 _____ () C:\Users\Richerts\Downloads\Sicherung_Millionenshow_AntikesGriechenland.zip
2014-06-01 21:59 - 2014-06-01 21:59 - 00102978 _____ () C:\Users\Richerts\Downloads\12Maerchen.zip
2014-05-31 12:12 - 2014-05-31 12:12 - 00000000 ____D () C:\Users\Richerts\Documents\Eendsoft
2014-05-31 12:12 - 2014-05-31 12:12 - 00000000 ____D () C:\ProgramData\firebird
2014-05-31 12:10 - 2014-05-31 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picto-Selector
2014-05-31 12:03 - 2014-05-31 12:10 - 00000000 ____D () C:\Program Files\Picto Selector
2014-05-31 11:59 - 2014-05-31 12:03 - 230896024 _____ (M.C. van der Kooij ) C:\Users\Richerts\Downloads\setup_complete.exe
2014-05-31 09:23 - 2014-05-31 09:23 - 00003332 _____ () C:\Users\Richerts\Downloads\McPower_Flag_of_Germany_(with_wind).svg
2014-05-31 09:14 - 2014-05-31 09:14 - 02086912 _____ () C:\Users\Richerts\Downloads\UE-Saeuren_im_Alltag.ppt
2014-05-30 23:48 - 2014-05-30 23:54 - 00000000 ____D () C:\Users\Richerts\Documents\Calibre-Bibliothek
2014-05-30 23:48 - 2014-05-30 23:48 - 00000000 ____D () C:\Users\Richerts\AppData\Local\calibre-cache
2014-05-30 23:47 - 2014-05-30 23:52 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\calibre
2014-05-30 23:47 - 2014-05-30 23:47 - 00000930 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk
2014-05-30 23:47 - 2014-05-30 23:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2014-05-30 23:47 - 2014-05-30 23:47 - 00000000 ____D () C:\Program Files\Calibre2
2014-05-30 23:44 - 2014-05-30 23:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Richerts\Downloads\Calibre 32 Bit - CHIP-Installer.exe
2014-05-30 23:39 - 2014-05-30 23:42 - 208218905 _____ () C:\Users\Richerts\Downloads\eBook_OER_fuer_alle_Version2.0.epub
2014-05-30 10:08 - 2014-06-23 23:32 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\Copernic
2014-05-30 10:08 - 2014-06-23 23:32 - 00000000 ____D () C:\Program Files\Common Files\Copernic
2014-05-30 02:35 - 2014-05-30 02:35 - 00456088 _____ (Check Point Software Technologies Ltd.) C:\Windows\system32\Drivers\vsdatant.sys
==================== One Month Modified Files and Folders =======
2014-06-29 23:08 - 2014-06-29 20:11 - 00022116 _____ () C:\Users\Richerts\Downloads\FRST.txt
2014-06-29 23:07 - 2014-06-29 20:11 - 00000000 ____D () C:\FRST
2014-06-29 23:06 - 2014-06-29 20:12 - 00000000 ____D () C:\Users\Richerts\Desktop\Trojaner Board
2014-06-29 23:05 - 2014-06-29 23:05 - 00001475 _____ () C:\Users\Richerts\Desktop\JRT.txt
2014-06-29 23:05 - 2009-07-14 06:34 - 00013792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-29 23:05 - 2009-07-14 06:34 - 00013792 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-29 23:01 - 2014-06-29 23:01 - 00000000 ____D () C:\Windows\ERUNT
2014-06-29 23:01 - 2014-06-29 23:00 - 01016261 _____ (Thisisu) C:\Users\Richerts\Downloads\JRT.exe
2014-06-29 22:57 - 2013-04-29 18:49 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-29 22:56 - 2014-06-12 10:08 - 00018566 _____ () C:\Windows\PFRO.log
2014-06-29 22:56 - 2014-06-12 10:08 - 00001133 _____ () C:\Windows\setupact.log
2014-06-29 22:56 - 2012-11-24 15:46 - 01230961 _____ () C:\Windows\WindowsUpdate.log
2014-06-29 22:56 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-29 22:55 - 2013-12-17 22:59 - 00000000 ____D () C:\AdwCleaner
2014-06-29 22:54 - 2013-04-29 18:49 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-29 22:51 - 2014-06-29 22:50 - 01342659 _____ () C:\Users\Richerts\Downloads\adwcleaner_3.213.exe
2014-06-29 22:50 - 2012-12-04 21:53 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-29 22:31 - 2014-06-29 22:30 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-29 22:30 - 2014-06-29 22:30 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-29 22:30 - 2014-06-29 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-29 22:30 - 2014-06-29 22:30 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-06-29 22:30 - 2012-11-24 23:01 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-06-29 22:28 - 2014-06-29 22:27 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Richerts\Desktop\mbam-setup-2.0.2.1012.exe
2014-06-29 22:17 - 2012-11-25 16:35 - 00000000 ____D () C:\ProgramData\Win7codecs
2014-06-29 22:04 - 2014-06-29 22:04 - 00001226 _____ () C:\Users\Richerts\Desktop\Revo Uninstaller.lnk
2014-06-29 22:04 - 2014-06-29 22:04 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-06-29 22:04 - 2014-06-29 22:03 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Richerts\Downloads\revosetup95.exe
2014-06-29 21:50 - 2013-06-14 10:38 - 00000000 ____D () C:\Users\Richerts\Desktop\Referendariat
2014-06-29 21:02 - 2013-09-30 22:09 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-06-29 20:57 - 2014-06-29 20:57 - 00003296 _____ () C:\Users\Richerts\Downloads\Gmer.txt.txt.zip
2014-06-29 20:52 - 2014-06-29 20:52 - 01110476 _____ () C:\Users\Richerts\Downloads\7z920.exe
2014-06-29 20:52 - 2014-06-29 20:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2014-06-29 20:52 - 2014-06-29 20:52 - 00000000 ____D () C:\Program Files\7-Zip
2014-06-29 20:14 - 2014-06-29 20:14 - 00380416 _____ () C:\Users\Richerts\Downloads\Gmer-19357.exe
2014-06-29 20:13 - 2014-06-29 20:12 - 00033909 _____ () C:\Users\Richerts\Downloads\Addition.txt
2014-06-29 20:11 - 2014-06-29 20:10 - 01073664 _____ (Farbar) C:\Users\Richerts\Downloads\FRST.exe
2014-06-29 20:09 - 2014-06-29 20:09 - 00000478 _____ () C:\Users\Richerts\Downloads\defogger_disable.log
2014-06-29 20:09 - 2014-06-29 20:09 - 00000000 _____ () C:\Users\Richerts\defogger_reenable
2014-06-29 20:09 - 2012-11-24 15:51 - 00000000 ____D () C:\Users\Richerts
2014-06-29 20:08 - 2014-06-29 20:08 - 00050477 _____ () C:\Users\Richerts\Downloads\Defogger.exe
2014-06-29 19:16 - 2014-06-29 19:14 - 00104960 _____ () C:\Users\Richerts\Desktop\Lied zum Abschied Kl 4a Rischenau.pub
2014-06-29 19:14 - 2014-06-29 19:11 - 00097792 _____ () C:\Users\Richerts\Downloads\Lied zum Abschied.pub
2014-06-28 20:16 - 2012-11-24 15:53 - 01622904 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-28 12:59 - 2013-07-27 23:02 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\KeePass
2014-06-28 00:01 - 2014-06-22 23:15 - 00008969 ____H () C:\Windows\system32\BTImages.dat
2014-06-27 23:59 - 2013-05-25 22:45 - 00000000 ____D () C:\Program Files\Schulfix
2014-06-27 23:58 - 2013-12-16 18:26 - 00000000 ____D () C:\Program Files\TuneUp Utilities 2014
2014-06-26 21:09 - 2014-06-26 21:09 - 154764088 _____ () C:\Users\Richerts\Documents\Amazing Modern Dancing Airport Flashmob 2014.mp4
2014-06-26 21:06 - 2014-06-22 22:07 - 00000000 ____D () C:\Users\Richerts\Desktop\Videos 8c
2014-06-23 23:32 - 2014-05-30 10:08 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\Copernic
2014-06-23 23:32 - 2014-05-30 10:08 - 00000000 ____D () C:\Program Files\Common Files\Copernic
2014-06-23 22:51 - 2014-06-23 22:51 - 00023843 _____ () C:\Users\Richerts\Downloads\UR_Entwurf_ Napoleon _ Kaiser der Franzosen.zip
2014-06-23 22:50 - 2014-06-23 22:28 - 07610880 _____ () C:\Users\Richerts\Downloads\Napoleon Bonaparte.ppt
2014-06-23 16:26 - 2012-12-01 22:03 - 00000000 ____D () C:\Users\Richerts\AppData\Local\Microsoft Help
2014-06-23 16:25 - 2014-06-23 16:25 - 00868352 _____ () C:\Users\Richerts\Downloads\206.ppt
2014-06-23 16:24 - 2014-06-23 16:24 - 01362944 _____ () C:\Users\Richerts\Downloads\202.ppt
2014-06-23 16:23 - 2014-06-23 16:23 - 00338432 _____ () C:\Users\Richerts\Downloads\195.ppt
2014-06-23 16:23 - 2014-06-23 16:23 - 00104960 _____ () C:\Users\Richerts\Downloads\197.ppt
2014-06-23 16:21 - 2014-06-23 16:21 - 00582144 _____ () C:\Users\Richerts\Downloads\193.ppt
2014-06-23 16:18 - 2014-06-23 16:18 - 00384512 _____ () C:\Users\Richerts\Downloads\199.ppt
2014-06-22 22:52 - 2014-06-22 22:52 - 00431135 _____ () C:\Windows\system32\Drivers\vsconfig.xml
2014-06-22 22:51 - 2014-06-22 22:51 - 00000732 _____ () C:\Users\Public\Desktop\ZoneAlarm Security.lnk
2014-06-22 22:51 - 2014-06-22 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
2014-06-22 22:51 - 2014-06-22 22:47 - 00000000 ____D () C:\Program Files\CheckPoint
2014-06-22 22:48 - 2014-06-22 22:48 - 03394856 _____ (Check Point Software Technologies Ltd.) C:\Users\Richerts\Downloads\zaSetupWeb_132_015_000 (1).exe
2014-06-22 22:47 - 2014-06-22 22:47 - 03394856 _____ (Check Point Software Technologies Ltd.) C:\Users\Richerts\Downloads\zaSetupWeb_132_015_000.exe
2014-06-22 22:47 - 2014-06-22 22:47 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\Check Point Software Technologies LTD
2014-06-22 22:47 - 2014-06-22 22:47 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-06-22 22:47 - 2014-06-22 22:47 - 00000000 ____D () C:\Program Files\Check Point Software Technologies LTD
2014-06-22 22:36 - 2013-03-29 19:39 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\QuickScan
2014-06-22 22:22 - 2014-06-22 22:21 - 00000000 ____D () C:\Users\Richerts\Desktop\Wir sind die Maus Wave Datei
2014-06-22 22:19 - 2014-06-22 22:19 - 00002178 _____ () C:\Users\Public\Desktop\Free Audio Converter.lnk
2014-06-22 22:19 - 2014-03-26 23:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2014-06-22 22:19 - 2014-03-26 23:02 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2014-06-22 22:19 - 2014-03-26 23:02 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-06-22 22:19 - 2013-05-10 22:16 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\DVDVideoSoft
2014-06-22 22:17 - 2014-06-22 22:17 - 34314288 _____ (DVDVideoSoft Ltd. ) C:\Users\Richerts\Downloads\FreeAudioConverter5.0.43.605.exe
2014-06-22 21:19 - 2014-06-22 21:19 - 00810950 _____ () C:\Users\Richerts\Downloads\sprachgeschichte_offen.zip
2014-06-22 18:01 - 2014-06-22 18:01 - 142293945 _____ () C:\Users\Richerts\Desktop\Die großen Entdecker der Welt_ Cook, Kolumbus, Vespucci, ect..mp4
2014-06-22 17:55 - 2014-06-22 17:55 - 165446210 _____ () C:\Users\Richerts\Desktop\DOKU_Christoph Kolumbus - Die Wahre Biografie_DEUTSCH _ 2014.mp4
2014-06-22 17:42 - 2014-06-22 17:42 - 00001251 _____ () C:\Users\Public\Desktop\YTD Video Downloader.lnk
2014-06-22 17:41 - 2014-06-22 17:41 - 11227432 _____ () C:\Users\Richerts\Downloads\YTDSetup481.exe
2014-06-18 17:02 - 2013-01-09 16:23 - 00000000 ____D () C:\Users\Richerts\Documents\Steuerfälle
2014-06-17 07:01 - 2014-04-26 13:12 - 00002175 _____ () C:\Users\Public\Desktop\SteuerSparErklärung 2014.lnk
2014-06-12 18:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-06-12 15:27 - 2014-05-07 21:53 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 13:52 - 2014-06-03 20:22 - 00000000 ____D () C:\Users\Richerts\Desktop\UPPs
2014-06-12 10:08 - 2014-06-12 10:08 - 00000000 _____ () C:\Windows\setuperr.log
2014-06-12 00:15 - 2013-08-24 12:55 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-12 00:15 - 2012-12-01 22:02 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-12 00:13 - 2012-11-24 16:51 - 92708840 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-11 17:51 - 2014-04-11 14:17 - 00000000 ____D () C:\Users\Richerts\Desktop\DUA_DUA_zeitreise_2_NRW_451026
2014-06-09 13:32 - 2014-06-09 13:32 - 00015872 _____ () C:\Users\Richerts\Downloads\Rueckmeldebogen Schuelerverhalten_positive Verstaerkung.xls
2014-06-08 10:48 - 2014-06-12 10:18 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 10:43 - 2014-06-12 10:18 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-05 17:05 - 2014-06-02 16:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-06-03 20:45 - 2014-06-03 20:45 - 00691572 _____ () C:\Users\Richerts\Downloads\kommunikation.hlp
2014-06-03 17:53 - 2014-06-03 17:53 - 00000000 ____D () C:\Users\Richerts\AppData\Local\PDFCreator
2014-06-02 19:00 - 2014-06-02 19:00 - 00417416 _____ () C:\Users\Richerts\Downloads\diversevorlagen.zip
2014-06-02 16:53 - 2014-06-02 16:53 - 13525781 _____ () C:\Users\Richerts\Downloads\tesseract-ocr-setup-3.02.02.exe
2014-06-02 16:50 - 2014-06-02 16:50 - 00000000 ____D () C:\Program Files\PDFCreator
2014-06-02 16:50 - 2014-06-02 16:49 - 01825064 _____ () C:\Users\Richerts\Downloads\tesseract-ocr-3.02.deu.tar.gz
2014-06-02 10:44 - 2014-06-02 10:44 - 25055960 _____ (pdfforge ) C:\Users\Richerts\Downloads\PDFCreator-1_9_3-setup.exe
2014-06-01 22:29 - 2014-06-01 22:29 - 00045541 _____ () C:\Users\Richerts\Downloads\marseillaise_military.mid
2014-06-01 22:28 - 2014-06-01 22:28 - 00007107 _____ () C:\Users\Richerts\Downloads\marseillaise.mid
2014-06-01 22:09 - 2014-06-01 22:09 - 03238941 _____ () C:\Users\Richerts\Downloads\Sicherung_Millionenshow_AntikesGriechenland.zip
2014-06-01 21:59 - 2014-06-01 21:59 - 00102978 _____ () C:\Users\Richerts\Downloads\12Maerchen.zip
2014-05-31 12:12 - 2014-05-31 12:12 - 00000000 ____D () C:\Users\Richerts\Documents\Eendsoft
2014-05-31 12:12 - 2014-05-31 12:12 - 00000000 ____D () C:\ProgramData\firebird
2014-05-31 12:10 - 2014-05-31 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picto-Selector
2014-05-31 12:10 - 2014-05-31 12:03 - 00000000 ____D () C:\Program Files\Picto Selector
2014-05-31 12:03 - 2014-05-31 11:59 - 230896024 _____ (M.C. van der Kooij ) C:\Users\Richerts\Downloads\setup_complete.exe
2014-05-31 09:23 - 2014-05-31 09:23 - 00003332 _____ () C:\Users\Richerts\Downloads\McPower_Flag_of_Germany_(with_wind).svg
2014-05-31 09:14 - 2014-05-31 09:14 - 02086912 _____ () C:\Users\Richerts\Downloads\UE-Saeuren_im_Alltag.ppt
2014-05-30 23:54 - 2014-05-30 23:48 - 00000000 ____D () C:\Users\Richerts\Documents\Calibre-Bibliothek
2014-05-30 23:52 - 2014-05-30 23:47 - 00000000 ____D () C:\Users\Richerts\AppData\Roaming\calibre
2014-05-30 23:48 - 2014-05-30 23:48 - 00000000 ____D () C:\Users\Richerts\AppData\Local\calibre-cache
2014-05-30 23:47 - 2014-05-30 23:47 - 00000930 _____ () C:\Users\Public\Desktop\calibre - E-book management.lnk
2014-05-30 23:47 - 2014-05-30 23:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\calibre - E-book Management
2014-05-30 23:47 - 2014-05-30 23:47 - 00000000 ____D () C:\Program Files\Calibre2
2014-05-30 23:44 - 2014-05-30 23:44 - 00961360 _____ (Chip Digital GmbH) C:\Users\Richerts\Downloads\Calibre 32 Bit - CHIP-Installer.exe
2014-05-30 23:42 - 2014-05-30 23:39 - 208218905 _____ () C:\Users\Richerts\Downloads\eBook_OER_fuer_alle_Version2.0.epub
2014-05-30 11:18 - 2014-06-12 10:19 - 17271296 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 11:02 - 2014-06-12 10:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 11:02 - 2014-06-12 10:19 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 10:44 - 2014-06-12 10:19 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 10:43 - 2014-06-12 10:19 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 10:42 - 2014-06-12 10:19 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-12 10:19 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 10:34 - 2014-06-12 10:19 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 10:33 - 2014-06-12 10:19 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 10:30 - 2014-06-12 10:19 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 10:28 - 2014-06-12 10:19 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 10:28 - 2014-06-12 10:19 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 10:27 - 2014-06-12 10:19 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 10:21 - 2014-06-12 10:19 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 10:16 - 2014-06-12 10:19 - 00368128 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 10:10 - 2014-06-12 10:19 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-12 10:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:04 - 2014-06-12 10:19 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:02 - 2014-06-12 10:19 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 09:57 - 2014-06-12 10:19 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 09:56 - 2014-06-12 10:19 - 04244992 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 09:54 - 2014-06-12 10:19 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 09:50 - 2014-06-12 10:19 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-12 10:19 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 09:40 - 2014-06-12 10:19 - 11725312 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:21 - 2014-06-12 10:19 - 01790976 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:15 - 2014-06-12 10:19 - 01143296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:13 - 2014-06-12 10:19 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 02:35 - 2014-05-30 02:35 - 00456088 _____ (Check Point Software Technologies Ltd.) C:\Windows\system32\Drivers\vsdatant.sys
Some content of TEMP:
====================
C:\Users\Richerts\AppData\Local\Temp\avgnt.exe
C:\Users\Richerts\AppData\Local\Temp\BackupSetup.exe
C:\Users\Richerts\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Richerts\AppData\Local\Temp\Quarantine.exe
C:\Users\Richerts\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Richerts\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-29 17:44
==================== End Of Log ============================ --- --- ---
--- --- ---
Vielen Dank für die Hilfe!
Gruß, Peter |