Hallo,
also Revo Uninstaller habe ich gemacht, jedoch nichts gefunden und habe mit Malewarebytes weiter gemacht und die anderen Scans durchgeführt.
Mein Avira hat einen Fehler in meiner ARK Library gefunden, konnte leider den Logfile nicht anhängen.
Danke für die schnelle Antwort!
hier meine Logfiles
Malewarebytes: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 06.07.2014 10:57:19, SYSTEM, PRINCESSLIZZY, Protection, Malware Protection, Starting,
Protection, 06.07.2014 10:57:19, SYSTEM, PRINCESSLIZZY, Protection, Malware Protection, Started,
Protection, 06.07.2014 10:57:19, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Starting,
Protection, 06.07.2014 10:57:19, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Started,
Update, 06.07.2014 10:57:23, SYSTEM, PRINCESSLIZZY, Manual, Rootkit Database, 2014.2.20.1, 2014.7.3.1,
Update, 06.07.2014 10:57:45, SYSTEM, PRINCESSLIZZY, Manual, Malware Database, 2014.3.4.9, 2014.7.6.3,
Protection, 06.07.2014 10:58:04, SYSTEM, PRINCESSLIZZY, Protection, Refresh, Starting,
Protection, 06.07.2014 10:58:04, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Stopping,
Protection, 06.07.2014 10:58:05, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Stopped,
Protection, 06.07.2014 10:58:10, SYSTEM, PRINCESSLIZZY, Protection, Refresh, Success,
Protection, 06.07.2014 10:58:10, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Starting,
Protection, 06.07.2014 10:58:10, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Started,
Protection, 06.07.2014 11:27:58, SYSTEM, PRINCESSLIZZY, Protection, Malware Protection, Starting,
Protection, 06.07.2014 11:27:58, SYSTEM, PRINCESSLIZZY, Protection, Malware Protection, Started,
Protection, 06.07.2014 11:27:58, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Starting,
Protection, 06.07.2014 11:28:41, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Failed,
Error, 06.07.2014 11:28:41, SYSTEM, PRINCESSLIZZY, Protection, MWAC::CreateList - Block List, 3221225473,
Protection, 06.07.2014 11:30:07, SYSTEM, PRINCESSLIZZY, Protection, Malware Protection, Starting,
Protection, 06.07.2014 11:30:07, SYSTEM, PRINCESSLIZZY, Protection, Malware Protection, Started,
Protection, 06.07.2014 11:30:07, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Starting,
Protection, 06.07.2014 11:31:24, SYSTEM, PRINCESSLIZZY, Protection, Malicious Website Protection, Started,
(end) AdwCleaner: Code:
# AdwCleaner v3.214 - Bericht erstellt am 06/07/2014 um 11:42:04
# Aktualisiert 29/06/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Elisa - PRINCESSLIZZY
# Gestartet von : C:\Users\Elisa\Downloads\adwcleaner_3.214.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : 70e6ca8c
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\DiisCoUntLocatoor
Ordner Gelöscht : C:\ProgramData\WowCoooupon
Ordner Gelöscht : C:\Program Files (x86)\Amazon Browser Bar
Ordner Gelöscht : C:\Program Files (x86)\CSBrowserHelper
Ordner Gelöscht : C:\Program Files (x86)\MediaPlayerV1
Ordner Gelöscht : C:\Program Files (x86)\MediaViewerV1
Ordner Gelöscht : C:\Program Files (x86)\MediaViewV1
Ordner Gelöscht : C:\Program Files (x86)\MediaWatchV1
Ordner Gelöscht : C:\Program Files (x86)\MetaCrawler
Ordner Gelöscht : C:\Program Files (x86)\RichMediaViewV1
Ordner Gelöscht : C:\Program Files (x86)\SearchProtect
Ordner Gelöscht : C:\Program Files (x86)\VideoPlayerV3
Ordner Gelöscht : C:\windows\SysWOW64\SearchProtect
Ordner Gelöscht : C:\Users\Elisa\AppData\Local\lollipop
Ordner Gelöscht : C:\Users\Elisa\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Elisa\AppData\Local\SwvUpdater
Ordner Gelöscht : C:\Users\Elisa\AppData\LocalLow\Smartbar
Ordner Gelöscht : C:\Users\Elisa\AppData\Roaming\0D0S1L2Z1P1B0T1P1B2Z
Ordner Gelöscht : C:\Users\Elisa\AppData\Roaming\goforfiles
Ordner Gelöscht : C:\Users\Elisa\AppData\Roaming\MetaCrawler
Ordner Gelöscht : C:\Users\Elisa\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Elisa\Documents\Optimizer Pro
Datei Gelöscht : C:\END
Datei Gelöscht : C:\windows\System32\Tasks\GoforFilesUpdate
Datei Gelöscht : C:\windows\Tasks\MetaCrawler.job
Datei Gelöscht : C:\windows\System32\Tasks\MetaCrawler
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\Users\Elisa\Desktop\Search.lnk
Verknüpfung Desinfiziert : C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
Verknüpfung Desinfiziert : C:\Users\Elisa\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Search.lnk
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\escort.escortIEPane.1
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SnapDo_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{D4EF7D75-52C9-4BCE-B6DC-0976EFAB4B0B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{BEAA0C04-ED15-4C17-800B-28716025A4E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4EF7D75-52C9-4BCE-B6DC-0976EFAB4B0B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4EF7D75-52C9-4BCE-B6DC-0976EFAB4B0B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{25A3A431-30BB-47C8-AD6A-E1063801134F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4EF7D75-52C9-4BCE-B6DC-0976EFAB4B0B}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{25A3A431-30BB-47C8-AD6A-E1063801134F}]
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C66F0B7A-BD67-4982-AF71-C6CA6E7F016F}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{26B19FA4-E8A1-4A1B-A163-1A1E46F830DD}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : HKCU\Software\distromatic
Schlüssel Gelöscht : HKCU\Software\GoforFiles
Schlüssel Gelöscht : HKCU\Software\lollipop
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\Software\BetterSurf
Schlüssel Gelöscht : HKLM\Software\GoforFiles
Schlüssel Gelöscht : HKLM\Software\InstallCore
Schlüssel Gelöscht : HKLM\Software\MediaPlayerV1
Schlüssel Gelöscht : HKLM\Software\MediaViewerV1
Schlüssel Gelöscht : HKLM\Software\MediaViewV1
Schlüssel Gelöscht : HKLM\Software\MediaWatchV1
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Codec Pack Packages
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16921
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v30.0 (de)
[ Datei : C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\dcxcqb2t.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [11169 octets] - [06/07/2014 11:41:11]
AdwCleaner[S0].txt - [9817 octets] - [06/07/2014 11:42:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9877 octets] ########## Junkware Removal Tool: Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Elisa on 06.07.2014 at 11:52:08,23
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\boost_interprocess"
~~~ FireFox
Emptied folder: C:\Users\Elisa\AppData\Roaming\mozilla\firefox\profiles\dcxcqb2t.default\minidumps [3 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06.07.2014 at 12:06:41,00
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und noch der gewünschte neue FRST:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-07-2014 01
Ran by Elisa (administrator) on PRINCESSLIZZY on 06-07-2014 12:31:07
Running from C:\Users\Elisa\Downloads
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\sSettings.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
() C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccsvchst.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Thisisu) C:\Users\Elisa\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191824 2012-08-10] (Realtek Semiconductor)
HKLM\...\Run: [BtTray] => C:\Program Files (x86)\Bluetooth Suite\BtTray.exe [766080 2012-12-05] (Qualcomm Atheros)
HKLM\...\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [128640 2012-12-05] (Atheros Communications)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [Bitcasa] => C:\Program Files\Bitcasa\Bitcasa.exe [3952128 2012-11-27] (Bitcasa, Inc)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [285240 2012-09-01] (Intel Corporation)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2994880 2012-08-15] (Symantec Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [97392 2012-08-15] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-08] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491120 2012-07-12] (CyberLink Corp.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-13] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-10-28] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-09-11] (DivX, LLC)
HKLM-x32\...\Run: [DivXUpdate] => C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe [1861968 2013-08-29] ()
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-01-20] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-07-03] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
AppInit_DLLs: C:\Program Files => C:\Program Files [0 2014-07-05] ()
AppInit_DLLs-x32: C:\Program Files => C:\Program Files [0 2014-07-05] ()
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: 1EldosIconOverlay -> {116DA551-D8D1-4F50-8758-983BF75C74E2} => C:\windows\SYSTEM32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: EldosIconOverlay -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: 1EldosIconOverlay -> {116DA551-D8D1-4F50-8758-983BF75C74E2} => C:\windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: EldosIconOverlay -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://samsung13.msn.com
SearchScopes: HKLM - DefaultScope {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://i.search.metacrawler.com/results.php?f=4&q={searchTerms}&a=ironmc2&cd=2XzuyEtN2Y1L1QzuyD0AyCyB0BtDyD0FzztBtB0CtAyBtDzytN0D0Tzu0CyCzytCtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu&cr=1409976367&ir=
SearchScopes: HKLM - {38B7222B-4B2A-4275-BD2A-70DC0BE165A6} URL = hxxp://i.search.metacrawler.com/results.php?f=4&q={searchTerms}&a=ironmc2&cd=2XzuyEtN2Y1L1QzuyD0AyCyB0BtDyD0FzztBtB0CtAyBtDzytN0D0Tzu0CyCzytCtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu&cr=1409976367&ir=
SearchScopes: HKLM - {78F63727-94FE-5EEB-6D5C-7F0354F5151E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
SearchScopes: HKLM-x32 - DefaultScope value is missing.
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation)
Toolbar: HKLM-x32 - metacrawler Toolbar - {7EACAC38-B7F6-4514-9DC1-3428A7964ABD} - C:\Program Files (x86)\metaCrawler\1.8.19.0\metacrawlerTlbr.dll No File
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\dcxcqb2t.default
FF Homepage: google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll ()
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 - C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX, LLC)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Elisa\AppData\Roaming\Mozilla\Firefox\Profiles\dcxcqb2t.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-15]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn
FF Extension: No Name - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\coFFPlgn [2014-02-15]
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF
FF Extension: No Name - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\IPSFF [2013-10-09]
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-10-10]
FF HKCU\...\Firefox\Extensions: [{b0b5a63d-7609-4029-823b-9a3acc4bd1ff}] - C:\Program Files (x86)\Re-markit\135.xpi
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171664 2012-11-06] (Adobe Systems Incorporated)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-03] (Avira Operations GmbH & Co. KG)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [231552 2012-12-05] (Qualcomm Atheros Commnucations)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2012-07-26] (Microsoft Corporation)
R2 Easy Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe [1591176 2012-11-30] (Samsung Electronics CO., LTD.) [File not signed]
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128896 2012-07-18] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3943104 2012-08-15] (Symantec Corporation)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 SWUpdateService; C:\Program Files (x86)\Samsung\SW Update\SWMAgent.exe [2878152 2012-12-21] (Samsung Electronics CO., LTD.)
S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [87728 2013-10-05] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-12-05] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [35496 2012-07-09] (Advanced Micro Devices, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-03] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-06-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\BASHDefs\20131022.001\BHDrvx64.sys [1524824 2013-10-23] (Symantec Corporation)
R3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [222360 2012-12-05] (Qualcomm Atheros)
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2012-12-05] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 cbfs3; C:\windows\system32\drivers\cbfs3.sys [352456 2012-08-06] (EldoS Corporation)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
S3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2013-08-27] (Symantec Corporation)
S3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [140376 2013-08-27] (Symantec Corporation)
S3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\IPSDefs\20131023.001\IDSvia64.sys [521816 2013-10-18] (Symantec Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-06] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20131023.024\ENG64.SYS [126040 2013-08-29] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.1.0.24\Definitions\VirusDefs\20131023.024\EX64.SYS [2099288 2013-08-29] (Symantec Corporation)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-09] (Corel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
S3 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
S3 SymDS; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
S3 SymEFA; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
S4 SymELAM; C:\Windows\system32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation)
S3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-08-26] (Symantec Corporation)
S3 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
S3 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-06 12:31 - 2014-07-06 12:31 - 00020684 _____ () C:\Users\Elisa\Downloads\FRST.txt
2014-07-06 12:30 - 2014-07-06 12:30 - 02084352 _____ (Farbar) C:\Users\Elisa\Downloads\FRST64.exe
2014-07-06 12:30 - 2014-07-06 12:30 - 00000000 ____D () C:\Users\Elisa\Downloads\FRST-OlderVersion
2014-07-06 12:28 - 2014-07-06 12:28 - 00000809 _____ () C:\Users\Elisa\Downloads\JRT.txt
2014-07-06 12:06 - 2014-07-06 12:06 - 00000809 _____ () C:\Users\Elisa\Desktop\JRT.txt
2014-07-06 11:52 - 2014-07-06 11:52 - 00000000 ____D () C:\windows\ERUNT
2014-07-06 11:51 - 2014-07-06 11:51 - 01016261 _____ (Thisisu) C:\Users\Elisa\Downloads\JRT.exe
2014-07-06 11:46 - 2014-07-06 11:46 - 00000000 ___RD () C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-06 11:42 - 2014-07-06 11:42 - 00001118 _____ () C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-06 11:42 - 2014-07-06 11:42 - 00001088 _____ () C:\Users\Elisa\Desktop\Search.lnk
2014-07-06 11:39 - 2014-07-06 11:42 - 00000000 ____D () C:\AdwCleaner
2014-07-06 11:38 - 2014-07-06 11:39 - 01346519 _____ () C:\Users\Elisa\Downloads\adwcleaner_3.214.exe
2014-07-06 11:35 - 2014-07-06 11:35 - 00002245 _____ () C:\Users\Elisa\Downloads\mbam.txt
2014-07-06 11:07 - 2014-07-06 11:07 - 00058046 _____ () C:\Users\Elisa\Documents\AVSCAN-20140705-212341-18F8F23A avira.txt
2014-07-06 10:57 - 2014-07-06 11:45 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-06 10:57 - 2014-07-06 10:57 - 00001128 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-06 10:57 - 2014-07-06 10:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-06 10:56 - 2014-07-06 10:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-06 10:56 - 2014-07-06 10:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-06 10:56 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-07-06 10:56 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-07-06 10:56 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-07-06 10:55 - 2014-07-06 10:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Elisa\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-06 10:48 - 2014-07-06 10:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Elisa\Downloads\revosetup95.exe
2014-07-06 10:48 - 2014-07-06 10:48 - 00001292 _____ () C:\Users\Elisa\Desktop\Revo Uninstaller.lnk
2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-05 23:02 - 2014-07-05 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2014-07-05 22:19 - 2014-07-05 22:20 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
2014-07-05 22:16 - 2014-07-05 22:19 - 233071424 _____ () C:\Users\Elisa\Downloads\kav14.0.0.4651abcdefg_de_6139.exe
2014-07-05 21:05 - 2014-07-05 21:05 - 00000000 _____ () C:\Users\Elisa\Downloads\Gmer.txt
2014-07-05 20:48 - 2014-07-05 20:48 - 00380416 _____ () C:\Users\Elisa\Downloads\Gmer-19357.exe
2014-07-03 19:36 - 2014-07-03 19:37 - 00059395 _____ () C:\Users\Elisa\Downloads\Addition.txt
2014-07-03 19:34 - 2014-07-06 12:31 - 00000000 ____D () C:\FRST
2014-07-03 19:29 - 2014-07-03 19:29 - 00050477 _____ () C:\Users\Elisa\Downloads\Defogger(1).exe
2014-07-03 19:27 - 2014-07-03 19:29 - 00000472 _____ () C:\Users\Elisa\Downloads\defogger_disable.log
2014-07-03 19:27 - 2014-07-03 19:27 - 00050477 _____ () C:\Users\Elisa\Downloads\Defogger.exe
2014-07-03 19:27 - 2014-07-03 19:27 - 00000000 _____ () C:\Users\Elisa\defogger_reenable
2014-07-02 14:50 - 2014-07-02 14:52 - 00006144 ___SH () C:\Users\Elisa\Desktop\Thumbs.db
2014-07-02 14:25 - 2014-07-02 15:24 - 00000000 ____D () C:\Users\Elisa\Desktop\Bewerbungen Juli
2014-07-01 18:37 - 2014-07-01 18:37 - 00000000 ____D () C:\Users\Elisa\Desktop\Mobile
2014-07-01 18:28 - 2014-07-01 18:40 - 00001606 _____ () C:\windows\setupact.log
2014-07-01 18:28 - 2014-07-01 18:28 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-07-01 18:28 - 2014-07-01 18:28 - 00000000 _____ () C:\windows\setuperr.log
2014-06-18 19:56 - 2014-07-06 11:42 - 00001826 _____ () C:\windows\PFRO.log
2014-06-17 15:57 - 2014-06-17 15:57 - 00000000 ____D () C:\Users\Elisa\AppData\Local\Macromedia
2014-06-17 15:56 - 2014-07-06 11:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-06-17 15:56 - 2014-06-17 15:56 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-06-17 15:53 - 2014-06-26 23:20 - 00000000 ____D () C:\Users\Elisa\Desktop\Duales Studium 2014
2014-06-17 13:00 - 2014-07-06 11:01 - 00806714 _____ () C:\windows\WindowsUpdate.log
2014-06-15 15:42 - 2014-06-15 15:44 - 04961831 _____ () C:\Users\Elisa\Downloads\ccsetup414.zip
2014-06-15 14:58 - 2014-06-15 14:59 - 00000000 ____D () C:\Users\Elisa\AppData\Roaming\Mozilla
2014-06-15 14:58 - 2014-06-15 14:59 - 00000000 ____D () C:\Users\Elisa\AppData\Local\Mozilla
2014-06-15 14:58 - 2014-06-15 14:58 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-15 14:58 - 2014-06-15 14:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-14 09:00 - 2014-05-31 07:16 - 00703992 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-06-14 09:00 - 2014-05-31 07:16 - 00105464 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-12 20:37 - 2014-05-24 04:46 - 19290112 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-12 20:37 - 2014-05-24 04:46 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-12 20:37 - 2014-05-24 04:45 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-12 20:37 - 2014-05-24 04:45 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-12 20:37 - 2014-05-24 03:25 - 00357888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-12 20:37 - 2014-05-24 03:25 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-12 20:36 - 2014-05-24 04:48 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-12 20:36 - 2014-05-24 04:47 - 02239488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-12 20:36 - 2014-05-24 04:47 - 01366016 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-12 20:36 - 2014-05-24 04:46 - 15368704 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-12 20:36 - 2014-05-24 04:46 - 03958784 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-12 20:36 - 2014-05-24 04:46 - 02650112 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-12 20:36 - 2014-05-24 04:46 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-12 20:36 - 2014-05-24 04:46 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-12 20:36 - 2014-05-24 04:45 - 01508864 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-12 20:36 - 2014-05-24 03:26 - 14365696 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-12 20:36 - 2014-05-24 03:26 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-12 20:36 - 2014-05-24 03:26 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-12 20:36 - 2014-05-24 03:25 - 01440768 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-12 20:35 - 2014-05-24 04:47 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2014-06-12 20:35 - 2014-05-24 04:47 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\UXInit.dll
2014-06-12 20:35 - 2014-05-24 04:46 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-06-12 20:35 - 2014-05-24 04:46 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-12 20:35 - 2014-05-24 04:46 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-06-12 20:35 - 2014-05-24 04:46 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-12 20:35 - 2014-05-24 04:46 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-12 20:35 - 2014-05-24 03:26 - 01766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-12 20:35 - 2014-05-24 03:26 - 01141248 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-12 20:35 - 2014-05-24 03:26 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-12 20:35 - 2014-05-24 03:26 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 13731328 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 02862080 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 02050560 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-12 20:35 - 2014-05-24 03:25 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-12 20:35 - 2014-05-24 03:09 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-12 20:35 - 2014-05-24 03:03 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-12 20:35 - 2014-05-24 00:37 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\uxtheme.dll
2014-06-12 20:34 - 2014-05-03 07:47 - 03246592 _____ (Microsoft Corporation) C:\windows\system32\rdpcorets.dll
2014-06-12 20:34 - 2014-05-03 05:34 - 00235520 _____ (Microsoft Corporation) C:\windows\system32\rdpudd.dll
2014-06-12 20:34 - 2014-04-30 00:32 - 01301504 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2014-06-12 20:34 - 2014-04-30 00:22 - 01023488 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2014-06-12 20:34 - 2014-04-03 13:19 - 00328024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\Classpnp.sys
2014-06-12 20:34 - 2014-04-03 05:44 - 00619008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
2014-06-12 20:34 - 2014-04-01 00:08 - 00387268 _____ () C:\windows\system32\ApnDatabase.xml
2014-06-12 20:34 - 2014-03-25 01:42 - 00305152 _____ (Microsoft Corporation) C:\windows\SysWOW64\wusa.exe
2014-06-12 20:34 - 2014-03-25 00:56 - 00309760 _____ (Microsoft Corporation) C:\windows\system32\wusa.exe
2014-06-12 20:31 - 2014-04-03 13:22 - 02233176 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2014-06-12 20:31 - 2014-03-07 02:47 - 01419264 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2014-06-12 20:31 - 2014-03-07 02:08 - 01845760 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
==================== One Month Modified Files and Folders =======
2014-07-06 12:31 - 2014-07-06 12:31 - 00020684 _____ () C:\Users\Elisa\Downloads\FRST.txt
2014-07-06 12:31 - 2014-07-03 19:34 - 00000000 ____D () C:\FRST
2014-07-06 12:30 - 2014-07-06 12:30 - 02084352 _____ (Farbar) C:\Users\Elisa\Downloads\FRST64.exe
2014-07-06 12:30 - 2014-07-06 12:30 - 00000000 ____D () C:\Users\Elisa\Downloads\FRST-OlderVersion
2014-07-06 12:29 - 2013-01-25 20:54 - 00795786 _____ () C:\windows\system32\perfh007.dat
2014-07-06 12:29 - 2013-01-25 20:54 - 00173668 _____ () C:\windows\system32\perfc007.dat
2014-07-06 12:29 - 2012-07-26 09:28 - 01858740 _____ () C:\windows\system32\PerfStringBackup.INI
2014-07-06 12:28 - 2014-07-06 12:28 - 00000809 _____ () C:\Users\Elisa\Downloads\JRT.txt
2014-07-06 12:15 - 2013-01-25 05:10 - 00000360 _____ () C:\windows\Tasks\Xerox PhotoCafe Communicator.job
2014-07-06 12:06 - 2014-07-06 12:06 - 00000809 _____ () C:\Users\Elisa\Desktop\JRT.txt
2014-07-06 12:00 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\sru
2014-07-06 11:57 - 2014-06-17 15:56 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-07-06 11:52 - 2014-07-06 11:52 - 00000000 ____D () C:\windows\ERUNT
2014-07-06 11:51 - 2014-07-06 11:51 - 01016261 _____ (Thisisu) C:\Users\Elisa\Downloads\JRT.exe
2014-07-06 11:48 - 2013-01-25 04:58 - 00000000 ____D () C:\ProgramData\WinClon
2014-07-06 11:46 - 2014-07-06 11:46 - 00000000 ___RD () C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
2014-07-06 11:45 - 2014-07-06 10:57 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-06 11:43 - 2013-01-25 04:48 - 00000868 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2014-07-06 11:43 - 2012-07-26 09:22 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-07-06 11:42 - 2014-07-06 11:42 - 00001118 _____ () C:\Users\Elisa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2014-07-06 11:42 - 2014-07-06 11:42 - 00001088 _____ () C:\Users\Elisa\Desktop\Search.lnk
2014-07-06 11:42 - 2014-07-06 11:39 - 00000000 ____D () C:\AdwCleaner
2014-07-06 11:42 - 2014-06-18 19:56 - 00001826 _____ () C:\windows\PFRO.log
2014-07-06 11:42 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\BBI
2014-07-06 11:39 - 2014-07-06 11:38 - 01346519 _____ () C:\Users\Elisa\Downloads\adwcleaner_3.214.exe
2014-07-06 11:35 - 2014-07-06 11:35 - 00002245 _____ () C:\Users\Elisa\Downloads\mbam.txt
2014-07-06 11:26 - 2014-04-30 20:19 - 03329488 _____ () C:\windows\system32\FNTCACHE.DAT
2014-07-06 11:07 - 2014-07-06 11:07 - 00058046 _____ () C:\Users\Elisa\Documents\AVSCAN-20140705-212341-18F8F23A avira.txt
2014-07-06 11:01 - 2014-06-17 13:00 - 00806714 _____ () C:\windows\WindowsUpdate.log
2014-07-06 10:57 - 2014-07-06 10:57 - 00001128 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-06 10:57 - 2014-07-06 10:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-06 10:56 - 2014-07-06 10:56 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-06 10:56 - 2014-07-06 10:56 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-06 10:55 - 2014-07-06 10:55 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Elisa\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-06 10:48 - 2014-07-06 10:48 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Elisa\Downloads\revosetup95.exe
2014-07-06 10:48 - 2014-07-06 10:48 - 00001292 _____ () C:\Users\Elisa\Desktop\Revo Uninstaller.lnk
2014-07-06 10:48 - 2014-07-06 10:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-05 23:02 - 2014-07-05 23:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2014-07-05 22:58 - 2013-01-25 05:06 - 00000000 ____D () C:\ProgramData\Temp
2014-07-05 22:53 - 2013-11-16 11:48 - 00000000 ____D () C:\Program Files (x86)\Microsoft Visual Studio 12.0
2014-07-05 22:49 - 2013-11-16 11:59 - 00000000 ____D () C:\Program Files (x86)\Microsoft SDKs
2014-07-05 22:47 - 2012-08-07 14:22 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-07-05 22:34 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-07-05 22:33 - 2013-11-16 11:48 - 00000000 ____D () C:\ProgramData\Package Cache
2014-07-05 22:20 - 2014-07-05 22:19 - 00000000 ____D () C:\ProgramData\Kaspersky Lab Setup Files
2014-07-05 22:19 - 2014-07-05 22:16 - 233071424 _____ () C:\Users\Elisa\Downloads\kav14.0.0.4651abcdefg_de_6139.exe
2014-07-05 21:09 - 2013-11-16 15:04 - 00000000 ____D () C:\Users\Elisa\Documents\Visual Studio 2013
2014-07-05 21:05 - 2014-07-05 21:05 - 00000000 _____ () C:\Users\Elisa\Downloads\Gmer.txt
2014-07-05 20:48 - 2014-07-05 20:48 - 00380416 _____ () C:\Users\Elisa\Downloads\Gmer-19357.exe
2014-07-03 22:26 - 2014-03-15 10:59 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\windows\system32\Drivers\avgntflt.sys
2014-07-03 19:39 - 2013-08-24 20:16 - 00462336 ___SH () C:\Users\Elisa\Downloads\Thumbs.db
2014-07-03 19:37 - 2014-07-03 19:36 - 00059395 _____ () C:\Users\Elisa\Downloads\Addition.txt
2014-07-03 19:29 - 2014-07-03 19:29 - 00050477 _____ () C:\Users\Elisa\Downloads\Defogger(1).exe
2014-07-03 19:29 - 2014-07-03 19:27 - 00000472 _____ () C:\Users\Elisa\Downloads\defogger_disable.log
2014-07-03 19:27 - 2014-07-03 19:27 - 00050477 _____ () C:\Users\Elisa\Downloads\Defogger.exe
2014-07-03 19:27 - 2014-07-03 19:27 - 00000000 _____ () C:\Users\Elisa\defogger_reenable
2014-07-03 19:27 - 2013-08-24 16:13 - 00000000 ____D () C:\Users\Elisa
2014-07-03 19:09 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\AUInstallAgent
2014-07-02 16:25 - 2014-01-10 00:24 - 00000000 ____D () C:\Users\Elisa\Desktop\Bewerbung 2014
2014-07-02 15:24 - 2014-07-02 14:25 - 00000000 ____D () C:\Users\Elisa\Desktop\Bewerbungen Juli
2014-07-02 14:59 - 2013-08-24 16:13 - 00000000 ____D () C:\Users\Elisa\AppData\Local\Packages
2014-07-02 14:52 - 2014-07-02 14:50 - 00006144 ___SH () C:\Users\Elisa\Desktop\Thumbs.db
2014-07-02 14:52 - 2014-01-23 15:32 - 00000000 ____D () C:\Users\Elisa\Desktop\Bewerbungen
2014-07-01 18:40 - 2014-07-01 18:28 - 00001606 _____ () C:\windows\setupact.log
2014-07-01 18:37 - 2014-07-01 18:37 - 00000000 ____D () C:\Users\Elisa\Desktop\Mobile
2014-07-01 18:28 - 2014-07-01 18:28 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-07-01 18:28 - 2014-07-01 18:28 - 00000000 _____ () C:\windows\setuperr.log
2014-07-01 11:50 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\LiveKernelReports
2014-06-30 22:55 - 2013-08-25 11:39 - 00000000 ____D () C:\Users\Elisa\AppData\Local\CrashDumps
2014-06-26 23:20 - 2014-06-17 15:53 - 00000000 ____D () C:\Users\Elisa\Desktop\Duales Studium 2014
2014-06-19 12:50 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\rescache
2014-06-17 15:57 - 2014-06-17 15:57 - 00000000 ____D () C:\Users\Elisa\AppData\Local\Macromedia
2014-06-17 15:56 - 2014-06-17 15:56 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-06-17 13:24 - 2013-08-24 16:23 - 00003596 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2669165515-361187302-876288576-1001
2014-06-15 15:47 - 2014-01-14 13:04 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-06-15 15:46 - 2012-08-06 00:07 - 00000000 ____D () C:\windows\Panther
2014-06-15 15:44 - 2014-06-15 15:42 - 04961831 _____ () C:\Users\Elisa\Downloads\ccsetup414.zip
2014-06-15 14:59 - 2014-06-15 14:58 - 00000000 ____D () C:\Users\Elisa\AppData\Roaming\Mozilla
2014-06-15 14:59 - 2014-06-15 14:58 - 00000000 ____D () C:\Users\Elisa\AppData\Local\Mozilla
2014-06-15 14:58 - 2014-06-15 14:58 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-06-15 14:58 - 2014-06-15 14:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-06-13 10:00 - 2013-01-25 04:48 - 00000870 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2014-06-12 21:54 - 2013-08-25 12:27 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-12 21:54 - 2012-07-26 09:59 - 00000000 ____D () C:\windows\CbsTemp
2014-06-12 21:49 - 2013-08-25 12:24 - 00000000 ____D () C:\windows\system32\MRT
2014-06-12 21:42 - 2013-08-25 12:24 - 95414520 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
Some content of TEMP:
====================
C:\Users\Elisa\AppData\Local\Temp\avgnt.exe
C:\Users\Elisa\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-25 16:27
==================== End Of Log ============================ --- --- --- |