MBAM Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 14.07.2014
Suchlauf-Zeit: 16:55:01
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.07.14.06
Rootkit Datenbank: v2014.07.09.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Moritz
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 306188
Verstrichene Zeit: 21 Min, 56 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, 1692, Löschen bei Neustart, [c3ab96095f1cdf571e7ae97460a131cf]
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, 1820, Löschen bei Neustart, [c2acc4db4932d1655b26eca4f809e61a]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 27
PUP.Optional.IePluginService.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IePluginServices, In Quarantäne, [c3ab96095f1cdf571e7ae97460a131cf],
PUP.Optional.WPM.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WindowsMangerProtect, In Quarantäne, [c2acc4db4932d1655b26eca4f809e61a],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\WindowsMangerProtect, In Quarantäne, [c2acc4db4932d1655b26eca4f809e61a],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}, In Quarantäne, [a9c59b04cdaeba7c9c1e3a5134ce14ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [a9c59b04cdaeba7c9c1e3a5134ce14ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{C292AD0A-C11F-479B-B8DB-743E72D283B0}, In Quarantäne, [a9c59b04cdaeba7c9c1e3a5134ce14ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [a9c59b04cdaeba7c9c1e3a5134ce14ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [a9c59b04cdaeba7c9c1e3a5134ce14ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc, In Quarantäne, [a9c59b04cdaeba7c9c1e3a5134ce14ec],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\esrv.mysearchdialESrvc.1, In Quarantäne, [a9c59b04cdaeba7c9c1e3a5134ce14ec],
PUP.Optional.Snapdo.T, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, In Quarantäne, [5b139f003a4154e280a7bbd40bf7d828],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [4727207fcbb0ef47beabf65c0df52fd1],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [73fbaff0314aa690cd9dbb97b64c55ab],
PUP.Optional.MySearchDial.A, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, In Quarantäne, [73fbaff0314aa690cd9dbb97b64c55ab],
PUP.Optional.Linkey.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}, In Quarantäne, [6905aef10972d2649e01b4a110f25ba5],
PUP.Optional.SupTab.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}, In Quarantäne, [1c5296095922df57a41ed87e30d21be5],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64, In Quarantäne, [05690f900774f73ff6fdad6a8084a55b],
Adware.EoRezo, HKLM\SOFTWARE\WOW6432NODE\FrEeSoFtToDaY, In Quarantäne, [3836e8b7a2d9a6900ceeaa53f21115eb],
PUP.Optional.WPM.A, HKLM\SOFTWARE\WOW6432NODE\supWindowsMangerProtect, In Quarantäne, [83eb0d9295e6ea4cf2460b0dad577987],
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\sweet-pageSoftware, In Quarantäne, [6a04d4cb4a317cba3069e9233dc78d73],
PUP.Optional.SystemK.A, HKLM\SOFTWARE\WOW6432NODE\SystemK, In Quarantäne, [d995049b9ae13006609f358ce2200df3],
PUP.Optional.SettingsManager.A, HKLM\SOFTWARE\WOW6432NODE\SYSTEMK\General, In Quarantäne, [cba3fca3df9c78bef3cb854fc53ddc24],
PUP.Optional.BundleInstaller.A, HKLM\SOFTWARE\WOW6432NODE\VITTALIA\AxtanInstaller, In Quarantäne, [f8760d92c3b81521dea6ecf392708977],
PUP.Optional.MySearchDial.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\mysearchdial.com, In Quarantäne, [b1bd544b8deebe780bf363955aa98d73],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [df8fd0cf0c6f092dd91d29b8e31f728e],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [f678940ba0dbd6601ede13e4877caa56],
PUP.Optional.Softonic.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\SOFTONIC\Universal Downloader, In Quarantäne, [bdb16a35cead5cda15e87b55f40ebf41],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0S0TzrtN0V1M1O1H, In Quarantäne, [f678940ba0dbd6601ede13e4877caa56]
Registrierungsdaten: 5
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Default_Search_URL, hxxp://www.sweet-page.com/web/?type=ds&ts=1405082504&from=cor&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD610722&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1405082504&from=cor&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD610722&q={searchTerms}),Ersetzt,[5a14faa555267eb830d43e62778d06fa]
PUP.Optional.SweetPage.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN|Search Page, hxxp://www.sweet-page.com/web/?type=ds&ts=1405082504&from=cor&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD610722&q={searchTerms}, Gut: (www.google.com), Schlecht: (hxxp://www.sweet-page.com/web/?type=ds&ts=1405082504&from=cor&uid=SAMSUNGXMZMTD128HAFV-000_S15MNYAD610722&q={searchTerms}),Ersetzt,[1c521887601be74f38aaa3f1eb19d12f]
PUP.Optional.Snapdo, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_256_CH&co=DE&userid=a3c74538-b554-53c7-8724-04899b539f86&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_256_CH&co=DE&userid=a3c74538-b554-53c7-8724-04899b539f86&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[de90603fabd046f0c44bc8d77f8509f7]
PUP.Optional.Snapdo, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|SearchAssistant, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_256_CH&co=DE&userid=a3c74538-b554-53c7-8724-04899b539f86&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_256_CH&co=DE&userid=a3c74538-b554-53c7-8724-04899b539f86&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[a0cebbe41b601f172ce4702f7292b24e]
PUP.Optional.SnapDo.A, HKU\S-1-5-21-1722788331-2345114465-2414518930-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_256_CH&co=DE&userid=a3c74538-b554-53c7-8724-04899b539f86&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}, Gut: (www.google.com), Schlecht: (hxxp://feed.snapdo.com/?publisher=ShoppingHelper&dpid=OB_256_CH&co=DE&userid=a3c74538-b554-53c7-8724-04899b539f86&searchtype=ds&q={searchTerms}&installDate={installDate}&barcodeid={barcodeID}&um={UM}),Ersetzt,[a9c516892457a690a40454411be96e92]
Ordner: 16
PUP.Optional.SimilarSites.A, C:\Users\Moritz\AppData\Roaming\SimilarSites, In Quarantäne, [ef7f059a116ae650c30d6343c63c7888],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\components, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices, Löschen bei Neustart, [0569930c285386b0e7dd8f2516eced13],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update, In Quarantäne, [0569930c285386b0e7dd8f2516eced13],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\UI, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.RocketFind.A, C:\Users\Moritz\AppData\Roaming\RocketUpdater\UpdateProc, In Quarantäne, [6c02b4eb413a6accb186358148ba4cb4],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect, Löschen bei Neustart, [65092f70e497f145c6728d2a28da39c7],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log, In Quarantäne, [65092f70e497f145c6728d2a28da39c7],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update, In Quarantäne, [65092f70e497f145c6728d2a28da39c7],
Dateien: 31
PUP.Optional.IePluginService.A, C:\ProgramData\IePluginServices\PluginService.exe, Löschen bei Neustart, [c3ab96095f1cdf571e7ae97460a131cf],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\ProtectWindowsManager.exe, Löschen bei Neustart, [c2acc4db4932d1655b26eca4f809e61a],
PUP.Optional.Europa, C:\Users\Moritz\Downloads\installer_whatsapp_2_11_163_Deutsch.exe, In Quarantäne, [b7b7dac5bbc07db9663fe395738ede22],
PUP.Optional.OptimumInstaller.A, C:\Users\Moritz\Downloads\Player-Chrome.exe, In Quarantäne, [29450a95f982bd7915deda7a9869b34d],
PUP.Optional.Softonic.A, C:\Users\Moritz\Downloads\SoftonicDownloader_fuer_facebookadesktop.exe, In Quarantäne, [3b333f6067148da9c590022508f941bf],
PUP.Optional.DefaultSearch.A, C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\default-search.xml, In Quarantäne, [ed81c6d913689a9c8632b024ed15a759],
PUP.Optional.Sanbreel.A, C:\Windows\System32\Drivers\{6fcd6092-9615-4f7f-8898-8df53980e5d2}Gw64.sys, In Quarantäne, [05690f900774f73ff6fdad6a8084a55b],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\chrome.manifest, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\install.rdf, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\components\SystemKHlpFF.xpt, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\DnsBHO.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\Error404BHO.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\MainBHO.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\NativeHelper.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\NewTabBHO.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\overlay.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\overlay.xul, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\RelatedSearch.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\RequestPreserver.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\SearchBHO.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.SystemK.A, C:\Users\Moritz\AppData\Roaming\Settings Manager\systemk\content\SettingManager.js, In Quarantäne, [fe70aaf57dfe2a0c56b991235aa88977],
PUP.Optional.IePluginServices.A, C:\ProgramData\IePluginServices\update\conf, In Quarantäne, [0569930c285386b0e7dd8f2516eced13],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\SearchProtect\CRASH_DUMP_P5308_T5312_D2014_07_11_T17_15_50.dmp, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\SearchProtect\CRASH_REPORT_P5308_T5312_D2014_07_11_T17_15_50.txt, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.SearchProtect.A, C:\Users\Moritz\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [115dabf4aad1fd39e6dfac0849b98e72],
PUP.Optional.RocketFind.A, C:\Users\Moritz\AppData\Roaming\RocketUpdater\UpdateProc\config.dat, In Quarantäne, [6c02b4eb413a6accb186358148ba4cb4],
PUP.Optional.RocketFind.A, C:\Users\Moritz\AppData\Roaming\RocketUpdater\UpdateProc\info.dat, In Quarantäne, [6c02b4eb413a6accb186358148ba4cb4],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\log\ProtectWindowsManager_2014-07-11[14-42-34-743].log, In Quarantäne, [65092f70e497f145c6728d2a28da39c7],
PUP.Optional.WPM.A, C:\ProgramData\WindowsMangerProtect\update\conf, In Quarantäne, [65092f70e497f145c6728d2a28da39c7],
Physische Sektoren: 0
(No malicious items detected)
(end) adwcleaner Code:
# AdwCleaner v3.215 - Bericht erstellt am 14/07/2014 um 17:27:39
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Moritz - PC
# Gestartet von : C:\Users\Moritz\Desktop\adwcleaner_3.215.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : webinstr
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Users\Moritz\AppData\Roaming\pdfforge
Ordner Gelöscht : C:\Users\Moritz\AppData\Roaming\RocketUpdater
Ordner Gelöscht : C:\Users\Moritz\AppData\Roaming\Settings Manager
Ordner Gelöscht : C:\Users\Moritz\AppData\Roaming\WSE Rocket
Ordner Gelöscht : C:\Users\Moritz\Documents\PC Speed Maximizer
Ordner Gelöscht : C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Datei Gelöscht : C:\windows\SysWOW64\RegistryHelperLM.ocx
Datei Gelöscht : C:\Users\Moritz\AppData\Roaming\aps.uninstall.scan.results
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WajamInternetEnhancer_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2476}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\FreeSoftToday
Schlüssel Gelöscht : HKCU\Software\Linkey
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\TutoTag
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\blockAndSurf
Schlüssel Gelöscht : HKLM\Software\SupTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\Tutorials
Schlüssel Gelöscht : HKLM\Software\Vittalia
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WSE Rocket
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.17028
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Extension] : bopakagnckmlgajfccecajhnimjiiedh
*************************
AdwCleaner[R0].txt - [5243 octets] - [14/07/2014 17:25:46]
AdwCleaner[S0].txt - [4595 octets] - [14/07/2014 17:27:39]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4655 octets] ########## JRT Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Moritz on 14.07.2014 at 17:36:16,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{C38821FB-3F9F-4DED-98EF-1D38D584F2DF}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Moritz\appdata\locallow\sitefinder"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.07.2014 at 17:55:22,98
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST
[CODE]
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-07-2014
Ran by Moritz (administrator) on PC on 14-07-2014 18:00:03
Running from C:\Users\Moritz\Desktop
Platform: Windows 8 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\creator-ws.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\n360.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsCmdServer.exe
(Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsEventHandler.exe
(Samsung Electronics CO., LTD.) C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\S Agent\CommonAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Support Center\GuaranaAgent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkManagerDMS.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkDMS.exe
(Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64128 2013-04-24] ()
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2889072 2013-03-25] (ELAN Microelectronics Corp.)
HKLM\...\Run: [Bitcasa] => C:\Program Files\Bitcasa\Bitcasa.exe [3965904 2013-06-06] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [597576 2013-07-05] (Copyright 2013 SAMSUNG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-05-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKU\S-1-5-21-1722788331-2345114465-2414518930-1001\...\Run: [GoogleChromeAutoLaunch_225DAFE3604C951CC7D8B456A1D302B2] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-06-05] (Google Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: 1EldosIconOverlay -> {849440F9-3182-446D-86F2-400B3F951DDE} => C:\windows\SYSTEM32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: BitcasaIconOverlay -> {A6975448-A999-49BB-B3E4-7730CF6A82C0} => C:\Program Files\Bitcasa\ExplorerMenu.dll ()
ShellIconOverlayIdentifiers: BitcasaProgressOverlay -> {6FB8D52A-0064-45B2-B687-F596FEAD09C2} => C:\Program Files\Bitcasa\ExplorerMenu.dll ()
ShellIconOverlayIdentifiers: EldosIconOverlay -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\system32\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: OverlayExcluded -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: OverlayPending -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers: OverlayProtected -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\buShell.dll (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: 1EldosIconOverlay -> {849440F9-3182-446D-86F2-400B3F951DDE} => C:\windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
ShellIconOverlayIdentifiers-x32: EldosIconOverlay -> {5BB532A2-BF14-4CCC-86B7-71B81EF6F8BC} => C:\windows\SysWow64\CbFsMntNtf3.dll (EldoS Corporation)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://search.msn.com/spbasic.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,CustomizeSearch = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchURL = hxxp://home.microsoft.com/access/autosearch.asp?p=%s
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
URLSearchHook: HKLM-x32 - Default Value = {CCC7B159-1D8C-11E3-B2AD-F3EF3D58318D}
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {C38821FB-3F9F-4DED-98EF-1D38D584F2DF} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=vit0102&cd=2XzuyEtN2Y1L1QzuyEzz0DtBtByEtByD0FtByDtAzzyE0EtBtN0D0Tzu0SzzyCtAtN1L2XzutBtFtCzztFtBtFtDtN1L1Czu2X1L2ZtDtCtDtBtN1L1G1B1V1N2Y1L1Qzu2SyE0D0DtCzztAyB0EtGyEtC0BzytG0C0EyEtCtG0ByC0D0EtGyEtB0CyCyCyDyD0CyD0AtCyB2QtN1M1F1B2Z1V1N2Y1L1Qzu2StD0A0E0B0BtDtCyBtG0F0CyE0CtGzzyEtDyBtG0D0F0DyBtGtBtBzztBzyyC0EyD0DtAtCyC2Q&cr=242595159&ir=
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {C38821FB-3F9F-4DED-98EF-1D38D584F2DF} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASMJS
BHO: Lync Browser Helper - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine64\21.4.0.13\coIEPlg.dll (Symantec Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\IPS\IPSBHO.DLL (Symantec Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin-x32: samsung.com/SamsungLinkPCPlugin - C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll (Samsung)
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\IPSFF [2014-07-11]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2014-07-14]
FF HKCU\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
FF HKCU\...\Firefox\Extensions: [{B88D9CE3-7EFB-E080-6B66-0996F729CACD}] - C:\Program Files (x86)\di2BlockAndSurf\175.xpi
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Docs) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-07-13]
CHR Extension: (Google Drive) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-07-13]
CHR Extension: (YouTube) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-07-13]
CHR Extension: (Adblock Plus) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-07-13]
CHR Extension: (Google-Suche) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-07-13]
CHR Extension: (Norton Identity Protection) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2014-07-13]
CHR Extension: (Google Wallet) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-07-13]
CHR Extension: (Google Mail) - C:\Users\Moritz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-07-13]
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\Exts\Chrome.crx [2014-07-11]
==================== Services (Whitelisted) =================
R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [172104 2013-01-26] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.14\AllShareFrameworkManagerDMS.exe [404360 2013-06-18] (Samsung) [File not signed]
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [310400 2013-04-24] (Windows (R) Win 7 DDK provider)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2279608 2014-05-20] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99184 2013-03-25] (ELAN Microelectronics Corp.)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.4.0.13\N360.exe [265040 2014-06-27] (Symantec Corporation)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-06-26] (pdfforge GmbH)
R2 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-06-26] (pdfforge GmbH)
S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-06-26] (pdfforge GmbH)
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [605768 2013-07-05] (Copyright 2013 SAMSUNG)
R2 Settings Launcher; C:\Program Files (x86)\Samsung\Settings\CmdServer\SettingsLauncher.exe [1594928 2013-06-14] (Samsung Electronics CO., LTD.)
R2 SWUpdateService; C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe [3014704 2013-06-18] (Samsung Electronics CO., LTD.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-04-24] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2012-09-20] (Microsoft Corporation)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [94208 2013-02-14] (Advanced Micro Devices)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20140703.001\BHDrvx64.sys [1530160 2014-07-03] (Symantec Corporation)
S3 BTATH_HID; C:\Windows\system32\DRIVERS\btath_hid.sys [223432 2013-04-24] (Qualcomm Atheros)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-04-24] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R1 cbfs3; C:\windows\system32\drivers\cbfs3.sys [352448 2013-02-11] (EldoS Corporation)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1504000.00D\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [486192 2014-07-11] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142128 2014-07-11] (Symantec Corporation)
S3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [21840 2013-03-25] (ELAN Microelectronic Corp.)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20140711.001\IDSvia64.sys [525016 2014-07-10] (Symantec Corporation)
R3 MBAMProtector; C:\windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-14] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\windows\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20140713.021\ENG64.SYS [126040 2014-07-11] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20140713.021\EX64.SYS [2099288 2014-07-11] (Symantec Corporation)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-09] (Corel Corporation)
R3 RadioHIDMini; C:\Windows\System32\drivers\RadioHIDMini.sys [23408 2012-07-27] (Windows (R) Win 7 DDK provider)
R3 SRTSP; C:\Windows\System32\Drivers\N360x64\1504000.00D\SRTSP64.SYS [875736 2014-02-13] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1504000.00D\SRTSPX64.SYS [36952 2013-09-10] (Symantec Corporation)
R0 SymDS; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1504000.00D\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation)
S4 SymELAM; C:\Windows\system32\drivers\N360x64\1504000.00D\SymELAM.sys [23568 2013-09-10] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-07-11] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1504000.00D\Ironx64.SYS [264280 2013-09-27] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1504000.00D\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation)
S3 WUDFWpdComp; C:\Windows\system32\DRIVERS\WUDFRd.sys [198656 2012-07-26] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-14 18:00 - 2014-07-14 18:00 - 00021119 _____ () C:\Users\Moritz\Desktop\FRST.txt
2014-07-14 17:55 - 2014-07-14 17:55 - 00000840 _____ () C:\Users\Moritz\Desktop\JRT.txt
2014-07-14 17:36 - 2014-07-14 17:36 - 00000000 ____D () C:\windows\ERUNT
2014-07-14 17:34 - 2014-07-14 17:35 - 01016261 _____ (Thisisu) C:\Users\Moritz\Desktop\JRT.exe
2014-07-14 17:30 - 2014-07-14 17:30 - 00004755 _____ () C:\Users\Moritz\Desktop\AdwCleaner[S0].txt
2014-07-14 17:27 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\windows\SysWOW64\sqlite3.dll
2014-07-14 17:23 - 2014-07-14 17:30 - 00000000 ____D () C:\AdwCleaner
2014-07-14 17:23 - 2014-07-14 17:23 - 01348263 _____ () C:\Users\Moritz\Desktop\adwcleaner_3.215.exe
2014-07-14 17:22 - 2014-07-14 17:22 - 00015706 _____ () C:\Users\Moritz\Desktop\mbam.txt
2014-07-14 16:49 - 2014-07-14 17:28 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-14 16:48 - 2014-07-14 16:48 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-14 16:48 - 2014-07-14 16:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-14 16:48 - 2014-07-14 16:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-14 16:48 - 2014-07-14 16:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-14 16:48 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-07-14 16:48 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-07-14 16:48 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-07-14 16:45 - 2014-07-14 16:46 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-14 13:15 - 2014-07-14 13:15 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-07-13 18:49 - 2014-07-13 18:49 - 00026768 _____ () C:\Users\Moritz\Desktop\combofix.txt
2014-07-13 18:32 - 2014-07-13 18:32 - 00026768 _____ () C:\ComboFix.txt
2014-07-13 18:03 - 2014-07-13 18:03 - 00001123 _____ () C:\Users\Moritz\Desktop\ComboFix - Verknüpfung.lnk
2014-07-13 17:38 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-07-13 17:38 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-07-13 17:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-07-13 17:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-07-13 17:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-07-13 17:38 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\windows\SWXCACLS.exe
2014-07-13 17:38 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-07-13 17:38 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-07-13 17:38 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-07-13 17:34 - 2014-07-13 18:32 - 00000000 ____D () C:\Qoobox
2014-07-13 17:33 - 2014-07-13 18:27 - 00000000 ____D () C:\windows\erdnt
2014-07-13 17:32 - 2014-07-13 17:33 - 05218814 ____R (Swearware) C:\Users\Moritz\Downloads\ComboFix.exe
2014-07-13 17:20 - 2014-07-13 17:20 - 00001268 _____ () C:\Users\Moritz\Desktop\Revo Uninstaller.lnk
2014-07-13 17:20 - 2014-07-13 17:20 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-13 17:19 - 2014-07-13 17:20 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Moritz\Downloads\revosetup95.exe
2014-07-13 15:31 - 2014-07-13 15:31 - 00007628 _____ () C:\Users\Moritz\Desktop\GMER.txt
2014-07-13 15:26 - 2014-07-13 15:26 - 00280368 _____ () C:\windows\Minidump\071314-12698-01.dmp
2014-07-13 15:11 - 2014-07-13 15:37 - 00000246 _____ () C:\Users\Moritz\Downloads\defogger_enable.log
2014-07-13 15:10 - 2014-07-13 15:10 - 00380416 _____ () C:\Users\Moritz\Downloads\Gmer-19357 (1).exe
2014-07-13 15:10 - 2014-07-13 15:10 - 00380416 _____ () C:\Users\Moritz\Downloads\Gmer-19357 (1) (1).exe
2014-07-13 15:10 - 2014-07-13 15:10 - 00380416 _____ () C:\Users\Moritz\Desktop\Gmer-19357.exe
2014-07-13 15:09 - 2014-07-13 15:09 - 00038745 _____ () C:\Users\Moritz\Desktop\Addition.txt
2014-07-13 15:07 - 2014-07-13 15:08 - 00038745 _____ () C:\Users\Moritz\Downloads\Addition.txt
2014-07-13 15:05 - 2014-07-14 18:00 - 00000000 ____D () C:\FRST
2014-07-13 15:05 - 2014-07-13 15:08 - 00063725 _____ () C:\Users\Moritz\Downloads\FRST.txt
2014-07-13 15:00 - 2014-07-13 15:00 - 02086912 _____ (Farbar) C:\Users\Moritz\Desktop\FRST64.exe
2014-07-13 14:57 - 2014-07-13 15:37 - 00000474 _____ () C:\Users\Moritz\Desktop\defogger_disable.log
2014-07-13 14:57 - 2014-07-13 14:57 - 00050477 _____ () C:\Users\Moritz\Downloads\Defogger.exe
2014-07-13 12:37 - 2014-07-13 12:37 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-13 12:37 - 2014-07-13 12:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-13 12:35 - 2014-07-14 17:40 - 00001116 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-13 12:35 - 2014-07-14 17:28 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-13 12:35 - 2014-07-13 12:37 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-13 12:35 - 2014-07-13 12:35 - 00004088 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-07-13 12:35 - 2014-07-13 12:35 - 00003852 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-07-13 12:34 - 2014-07-13 12:37 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Google
2014-07-13 12:34 - 2014-07-13 12:34 - 00895120 _____ (Google Inc.) C:\Users\Moritz\Downloads\ChromeSetup.exe
2014-07-13 12:11 - 2014-07-13 12:11 - 00448512 _____ (OldTimer Tools) C:\Users\Moritz\Downloads\TFC.exe
2014-07-13 04:44 - 2014-07-13 04:45 - 03459272 _____ () C:\windows\system32\FNTCACHE.DAT
2014-07-12 18:23 - 2014-07-12 18:23 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-07-11 17:55 - 2014-07-13 04:45 - 00000000 ____D () C:\NPE
2014-07-11 17:52 - 2014-07-11 17:52 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360
2014-07-11 17:51 - 2014-07-13 04:48 - 00000000 ____D () C:\Users\Moritz\AppData\Local\NPE
2014-07-11 17:07 - 2014-06-26 22:53 - 00703968 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-07-11 17:07 - 2014-06-26 22:53 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-11 17:04 - 2014-07-11 17:15 - 00000000 ___RD () C:\windows\BrowserChoice
2014-07-11 16:47 - 2014-07-11 16:47 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-11 16:47 - 2014-07-07 17:04 - 00057528 _____ (Corsica) C:\windows\system32\Drivers\webinstr.sys
2014-07-11 16:46 - 2014-07-11 16:46 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-07-11 16:27 - 2014-07-11 17:52 - 00003206 _____ () C:\windows\System32\Tasks\Norton WSC Integration
2014-07-11 16:27 - 2014-07-11 17:52 - 00002319 _____ () C:\Users\Public\Desktop\Norton 360.lnk
2014-07-11 16:27 - 2014-07-11 16:27 - 00177752 _____ (Symantec Corporation) C:\windows\system32\Drivers\SYMEVENT64x86.SYS
2014-07-11 16:27 - 2014-07-11 16:27 - 00008222 _____ () C:\windows\system32\Drivers\SYMEVENT64x86.CAT
2014-07-11 16:27 - 2014-07-11 16:27 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared
2014-07-11 16:23 - 2014-07-11 17:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
2014-07-11 16:23 - 2014-07-11 17:52 - 00000000 ____D () C:\windows\system32\Drivers\N360x64
2014-07-11 16:23 - 2014-07-11 16:23 - 00000000 ____D () C:\Program Files (x86)\Norton 360
2014-07-11 16:15 - 2014-07-11 16:15 - 00000264 _____ () C:\Users\Moritz\Desktop\Cut the Rope.url
2014-07-11 16:14 - 2014-07-11 16:14 - 00000000 ____D () C:\ProgramData\PCSettings
2014-07-11 14:33 - 2014-07-11 14:33 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\PDF Architect 2
2014-07-11 14:30 - 2014-07-11 14:39 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-07-11 14:30 - 2014-07-11 14:30 - 00001017 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-07-11 14:30 - 2014-07-11 14:30 - 00000000 ____D () C:\Users\Moritz\Documents\PDF Architect 2
2014-07-11 14:30 - 2014-07-11 14:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-07-11 14:28 - 2014-07-11 14:33 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-07-11 14:28 - 2014-07-11 14:28 - 00001035 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-07-11 14:28 - 2014-07-11 14:28 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-07-11 14:28 - 2014-07-11 14:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-07-11 14:28 - 2014-04-25 17:44 - 00137000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSMAPI32.OCX
2014-07-11 14:28 - 2014-04-25 17:44 - 00110264 _____ (pdfforge GmbH) C:\windows\system32\pdfcmon.dll
2014-07-11 14:28 - 2014-04-25 17:44 - 00023552 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSMPIDE.DLL
2014-07-11 14:28 - 1998-07-06 18:56 - 00125712 _____ (Microsoft Corporation) C:\windows\SysWOW64\VB6DE.DLL
2014-07-11 14:28 - 1998-07-06 18:55 - 00158208 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSCMCDE.DLL
2014-07-11 14:28 - 1998-07-06 18:55 - 00064512 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSCC2DE.DLL
2014-07-11 14:25 - 2014-07-11 14:26 - 27843432 _____ (pdfforge ) C:\Users\Moritz\Downloads\PDFCreator-1_7_3_setup.exe
2014-07-10 16:58 - 2014-07-10 16:58 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\OpenOffice
2014-07-09 15:11 - 2014-07-01 00:42 - 00702464 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-07-09 15:11 - 2014-07-01 00:42 - 00394240 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2014-07-09 15:11 - 2014-07-01 00:42 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2014-07-09 15:11 - 2014-06-28 05:35 - 00556544 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-07-09 13:15 - 2014-06-18 01:27 - 01440256 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2014-07-09 13:15 - 2014-06-18 01:24 - 01557504 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2014-07-09 13:15 - 2014-06-11 06:18 - 04038144 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-07-09 13:15 - 2014-06-03 00:33 - 00265216 _____ (Microsoft Corporation) C:\windows\system32\InkEd.dll
2014-07-09 13:15 - 2014-05-30 01:31 - 00452608 _____ (Microsoft Corporation) C:\windows\SysWOW64\SHCore.dll
2014-07-09 13:15 - 2014-05-30 01:03 - 00588288 _____ (Microsoft Corporation) C:\windows\system32\SHCore.dll
2014-07-09 13:15 - 2014-05-30 01:02 - 01281536 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2014-07-09 13:15 - 2014-05-30 01:02 - 00439808 _____ (Microsoft Corporation) C:\windows\system32\lsm.dll
2014-07-09 13:15 - 2014-05-03 08:34 - 06974808 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2014-07-09 13:15 - 2014-05-03 08:33 - 01824808 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2014-07-09 13:15 - 2014-05-03 06:51 - 01408976 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2014-07-09 13:15 - 2014-05-02 00:37 - 01023488 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2014-07-09 13:15 - 2014-04-30 00:32 - 00126464 _____ (Microsoft Corporation) C:\windows\system32\Robocopy.exe
2014-07-09 13:15 - 2014-04-24 01:51 - 00566784 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2014-07-09 13:15 - 2014-04-24 01:38 - 00693760 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2014-07-09 13:15 - 2014-02-08 06:34 - 00071168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hdaudbus.sys
2014-07-09 13:14 - 2014-06-19 04:12 - 02239488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-07-09 13:14 - 2014-06-19 04:12 - 01366528 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-07-09 13:14 - 2014-06-19 04:12 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2014-07-09 13:14 - 2014-06-19 04:12 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\UXInit.dll
2014-07-09 13:14 - 2014-06-19 04:12 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-07-09 13:14 - 2014-06-19 04:11 - 19277312 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-07-09 13:14 - 2014-06-19 04:11 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-07-09 13:14 - 2014-06-19 04:11 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 15369728 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 03959296 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 02650624 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00255488 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-07-09 13:14 - 2014-06-19 04:10 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-07-09 13:14 - 2014-06-19 04:09 - 01508864 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-07-09 13:14 - 2014-06-19 02:53 - 14368768 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-07-09 13:14 - 2014-06-19 02:53 - 01766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-07-09 13:14 - 2014-06-19 02:53 - 01141760 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-07-09 13:14 - 2014-06-19 02:53 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-07-09 13:14 - 2014-06-19 02:53 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-07-09 13:14 - 2014-06-19 02:53 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-07-09 13:14 - 2014-06-19 02:53 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 13732352 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 02863616 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 02051072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 01440768 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-07-09 13:14 - 2014-06-19 02:52 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 00357888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-07-09 13:14 - 2014-06-19 02:52 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-07-09 13:14 - 2014-06-19 02:33 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-07-09 13:14 - 2014-06-19 02:30 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-07-09 13:14 - 2014-06-19 00:05 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\uxtheme.dll
2014-07-09 13:14 - 2014-05-30 00:24 - 00576512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\afd.sys
2014-07-09 13:14 - 2014-04-30 00:32 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\Robocopy.exe
2014-07-09 13:14 - 2014-04-24 01:51 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 13:14 - 2014-04-24 01:38 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-09 13:13 - 2014-06-06 16:06 - 00596480 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-07-09 13:13 - 2014-06-06 12:17 - 00497152 _____ (Microsoft Corporation) C:\windows\SysWOW64\qedit.dll
2014-07-08 11:05 - 2014-07-08 11:05 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk
2014-07-08 11:05 - 2014-07-08 11:05 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-07-08 11:04 - 2014-07-08 11:04 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-07-08 10:47 - 2014-07-08 10:48 - 00961360 _____ (Chip Digital GmbH) C:\Users\Moritz\Downloads\OpenOffice - CHIP-Installer.exe
2014-07-02 12:51 - 2014-07-02 13:52 - 00000000 ____D () C:\Users\Moritz\Desktop\uni
2014-06-26 21:20 - 2014-06-26 21:20 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_wpdcomp_01_11_00.Wdf
2014-06-26 17:17 - 2014-06-26 17:17 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-06-22 12:02 - 2014-07-13 15:26 - 529026925 _____ () C:\windows\MEMORY.DMP
2014-06-22 12:02 - 2014-07-13 15:26 - 00000000 ____D () C:\windows\Minidump
2014-06-22 12:02 - 2014-06-22 12:02 - 00262144 _____ () C:\windows\Minidump\062214-10795-01.dmp
2014-06-20 11:02 - 2014-06-20 11:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-06-20 11:02 - 2014-06-20 11:02 - 00000000 ____D () C:\Program Files\McAfee Security Scan
==================== One Month Modified Files and Folders =======
2014-07-14 18:00 - 2014-07-14 18:00 - 00021119 _____ () C:\Users\Moritz\Desktop\FRST.txt
2014-07-14 18:00 - 2014-07-13 15:05 - 00000000 ____D () C:\FRST
2014-07-14 18:00 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\sru
2014-07-14 17:55 - 2014-07-14 17:55 - 00000840 _____ () C:\Users\Moritz\Desktop\JRT.txt
2014-07-14 17:40 - 2014-07-13 12:35 - 00001116 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-14 17:39 - 2013-07-09 06:07 - 01751865 _____ () C:\windows\WindowsUpdate.log
2014-07-14 17:36 - 2014-07-14 17:36 - 00000000 ____D () C:\windows\ERUNT
2014-07-14 17:35 - 2014-07-14 17:34 - 01016261 _____ (Thisisu) C:\Users\Moritz\Desktop\JRT.exe
2014-07-14 17:33 - 2013-07-10 00:16 - 00785550 _____ () C:\windows\system32\perfh013.dat
2014-07-14 17:33 - 2013-07-10 00:16 - 00158586 _____ () C:\windows\system32\perfc013.dat
2014-07-14 17:33 - 2013-07-10 00:14 - 00785746 _____ () C:\windows\system32\perfh015.dat
2014-07-14 17:33 - 2013-07-10 00:14 - 00159396 _____ () C:\windows\system32\perfc015.dat
2014-07-14 17:33 - 2013-07-10 00:11 - 00753134 _____ () C:\windows\system32\perfh007.dat
2014-07-14 17:33 - 2013-07-10 00:11 - 00155826 _____ () C:\windows\system32\perfc007.dat
2014-07-14 17:33 - 2013-07-10 00:09 - 00790022 _____ () C:\windows\system32\perfh00C.dat
2014-07-14 17:33 - 2013-07-10 00:09 - 00155084 _____ () C:\windows\system32\perfc00C.dat
2014-07-14 17:33 - 2012-07-26 09:28 - 04579878 _____ () C:\windows\system32\PerfStringBackup.INI
2014-07-14 17:31 - 2013-07-09 09:22 - 00000000 ____D () C:\ProgramData\WinClon
2014-07-14 17:30 - 2014-07-14 17:30 - 00004755 _____ () C:\Users\Moritz\Desktop\AdwCleaner[S0].txt
2014-07-14 17:30 - 2014-07-14 17:23 - 00000000 ____D () C:\AdwCleaner
2014-07-14 17:28 - 2014-07-14 16:49 - 00122584 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-14 17:28 - 2014-07-13 12:35 - 00001112 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-14 17:28 - 2012-08-05 23:07 - 00726500 _____ () C:\windows\PFRO.log
2014-07-14 17:28 - 2012-07-26 09:22 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-07-14 17:28 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\BBI
2014-07-14 17:23 - 2014-07-14 17:23 - 01348263 _____ () C:\Users\Moritz\Desktop\adwcleaner_3.215.exe
2014-07-14 17:22 - 2014-07-14 17:22 - 00015706 _____ () C:\Users\Moritz\Desktop\mbam.txt
2014-07-14 17:15 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\system32\NDF
2014-07-14 17:04 - 2014-05-01 00:48 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-07-14 16:48 - 2014-07-14 16:48 - 00001106 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-14 16:48 - 2014-07-14 16:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-14 16:48 - 2014-07-14 16:48 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-14 16:48 - 2014-07-14 16:48 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-14 16:46 - 2014-07-14 16:45 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Moritz\Downloads\mbam-setup-2.0.2.1012.exe
2014-07-14 16:30 - 2013-07-09 09:04 - 00065536 _____ () C:\windows\system32\spu_storage.bin
2014-07-14 13:15 - 2014-07-14 13:15 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-07-14 13:15 - 2012-07-26 09:21 - 00028180 _____ () C:\windows\setupact.log
2014-07-13 18:49 - 2014-07-13 18:49 - 00026768 _____ () C:\Users\Moritz\Desktop\combofix.txt
2014-07-13 18:36 - 2014-04-28 13:34 - 00003600 _____ () C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1722788331-2345114465-2414518930-1001
2014-07-13 18:32 - 2014-07-13 18:32 - 00026768 _____ () C:\ComboFix.txt
2014-07-13 18:32 - 2014-07-13 17:34 - 00000000 ____D () C:\Qoobox
2014-07-13 18:32 - 2013-07-09 09:28 - 00000000 ____D () C:\Users\EasySurvey
2014-07-13 18:32 - 2012-07-26 07:37 - 00000000 __RHD () C:\Users\Default
2014-07-13 18:27 - 2014-07-13 17:33 - 00000000 ____D () C:\windows\erdnt
2014-07-13 18:26 - 2012-07-26 07:26 - 00000215 _____ () C:\windows\system.ini
2014-07-13 18:14 - 2014-05-16 03:50 - 00000000 ____D () C:\Users\Moritz\AppData\Local\CrashDumps
2014-07-13 18:03 - 2014-07-13 18:03 - 00001123 _____ () C:\Users\Moritz\Desktop\ComboFix - Verknüpfung.lnk
2014-07-13 17:33 - 2014-07-13 17:32 - 05218814 ____R (Swearware) C:\Users\Moritz\Downloads\ComboFix.exe
2014-07-13 17:20 - 2014-07-13 17:20 - 00001268 _____ () C:\Users\Moritz\Desktop\Revo Uninstaller.lnk
2014-07-13 17:20 - 2014-07-13 17:20 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-13 17:20 - 2014-07-13 17:19 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Moritz\Downloads\revosetup95.exe
2014-07-13 16:30 - 2012-07-26 09:59 - 00000000 ____D () C:\windows\CbsTemp
2014-07-13 15:37 - 2014-07-13 15:11 - 00000246 _____ () C:\Users\Moritz\Downloads\defogger_enable.log
2014-07-13 15:37 - 2014-07-13 14:57 - 00000474 _____ () C:\Users\Moritz\Desktop\defogger_disable.log
2014-07-13 15:37 - 2014-04-28 13:17 - 00000000 ____D () C:\Users\Moritz
2014-07-13 15:31 - 2014-07-13 15:31 - 00007628 _____ () C:\Users\Moritz\Desktop\GMER.txt
2014-07-13 15:26 - 2014-07-13 15:26 - 00280368 _____ () C:\windows\Minidump\071314-12698-01.dmp
2014-07-13 15:26 - 2014-06-22 12:02 - 529026925 _____ () C:\windows\MEMORY.DMP
2014-07-13 15:26 - 2014-06-22 12:02 - 00000000 ____D () C:\windows\Minidump
2014-07-13 15:10 - 2014-07-13 15:10 - 00380416 _____ () C:\Users\Moritz\Downloads\Gmer-19357 (1).exe
2014-07-13 15:10 - 2014-07-13 15:10 - 00380416 _____ () C:\Users\Moritz\Downloads\Gmer-19357 (1) (1).exe
2014-07-13 15:10 - 2014-07-13 15:10 - 00380416 _____ () C:\Users\Moritz\Desktop\Gmer-19357.exe
2014-07-13 15:09 - 2014-07-13 15:09 - 00038745 _____ () C:\Users\Moritz\Desktop\Addition.txt
2014-07-13 15:08 - 2014-07-13 15:07 - 00038745 _____ () C:\Users\Moritz\Downloads\Addition.txt
2014-07-13 15:08 - 2014-07-13 15:05 - 00063725 _____ () C:\Users\Moritz\Downloads\FRST.txt
2014-07-13 15:00 - 2014-07-13 15:00 - 02086912 _____ (Farbar) C:\Users\Moritz\Desktop\FRST64.exe
2014-07-13 14:57 - 2014-07-13 14:57 - 00050477 _____ () C:\Users\Moritz\Downloads\Defogger.exe
2014-07-13 12:38 - 2014-04-28 13:37 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\Mozilla
2014-07-13 12:38 - 2014-04-28 13:37 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-13 12:37 - 2014-07-13 12:37 - 00002251 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-07-13 12:37 - 2014-07-13 12:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-07-13 12:37 - 2014-07-13 12:35 - 00000000 ____D () C:\Program Files (x86)\Google
2014-07-13 12:37 - 2014-07-13 12:34 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Google
2014-07-13 12:35 - 2014-07-13 12:35 - 00004088 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-07-13 12:35 - 2014-07-13 12:35 - 00003852 _____ () C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-07-13 12:34 - 2014-07-13 12:34 - 00895120 _____ (Google Inc.) C:\Users\Moritz\Downloads\ChromeSetup.exe
2014-07-13 12:11 - 2014-07-13 12:11 - 00448512 _____ (OldTimer Tools) C:\Users\Moritz\Downloads\TFC.exe
2014-07-13 04:48 - 2014-07-11 17:51 - 00000000 ____D () C:\Users\Moritz\AppData\Local\NPE
2014-07-13 04:45 - 2014-07-13 04:44 - 03459272 _____ () C:\windows\system32\FNTCACHE.DAT
2014-07-13 04:45 - 2014-07-11 17:55 - 00000000 ____D () C:\NPE
2014-07-12 18:23 - 2014-07-12 18:23 - 00000000 ___SD () C:\windows\system32\CompatTel
2014-07-12 18:23 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-12 18:23 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-12 18:23 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-07-12 18:23 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-12 18:23 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-07-12 18:23 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-07-12 18:23 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-07-11 17:55 - 2012-07-26 10:12 - 00000000 ___HD () C:\windows\ELAMBKUP
2014-07-11 17:54 - 2013-07-09 09:20 - 00000000 ____D () C:\ProgramData\Norton
2014-07-11 17:52 - 2014-07-11 17:52 - 00000000 ____D () C:\windows\System32\Tasks\Norton 360
2014-07-11 17:52 - 2014-07-11 16:27 - 00003206 _____ () C:\windows\System32\Tasks\Norton WSC Integration
2014-07-11 17:52 - 2014-07-11 16:27 - 00002319 _____ () C:\Users\Public\Desktop\Norton 360.lnk
2014-07-11 17:52 - 2014-07-11 16:23 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
2014-07-11 17:52 - 2014-07-11 16:23 - 00000000 ____D () C:\windows\system32\Drivers\N360x64
2014-07-11 17:15 - 2014-07-11 17:04 - 00000000 ___RD () C:\windows\BrowserChoice
2014-07-11 17:15 - 2014-04-28 13:17 - 00000000 ____D () C:\Users\Moritz\AppData\Local\Packages
2014-07-11 17:15 - 2012-08-05 23:11 - 00000000 ____D () C:\ProgramData\PRICache
2014-07-11 17:06 - 2012-07-26 07:26 - 00262144 ___SH () C:\windows\system32\config\ELAM
2014-07-11 17:04 - 2012-07-26 10:12 - 00000000 ___RD () C:\windows\ToastData
2014-07-11 17:04 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\WinStore
2014-07-11 17:04 - 2012-07-26 09:52 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-11 17:04 - 2012-07-26 07:38 - 00000000 ____D () C:\windows\system32\oobe
2014-07-11 17:03 - 2014-05-16 11:02 - 00000000 ____D () C:\windows\system32\MRT
2014-07-11 17:01 - 2014-05-16 11:02 - 96441528 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-07-11 16:47 - 2014-07-11 16:47 - 00000000 ____H () C:\windows\system32\Drivers\Msft_Kernel_webinstr_01009.Wdf
2014-07-11 16:46 - 2014-07-11 16:46 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-07-11 16:46 - 2012-07-26 10:12 - 00000000 ___HD () C:\windows\system32\GroupPolicy
2014-07-11 16:46 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\SysWOW64\GroupPolicy
2014-07-11 16:28 - 2012-07-26 07:26 - 00000194 _____ () C:\windows\win.ini
2014-07-11 16:27 - 2014-07-11 16:27 - 00177752 _____ (Symantec Corporation) C:\windows\system32\Drivers\SYMEVENT64x86.SYS
2014-07-11 16:27 - 2014-07-11 16:27 - 00008222 _____ () C:\windows\system32\Drivers\SYMEVENT64x86.CAT
2014-07-11 16:27 - 2014-07-11 16:27 - 00000000 ____D () C:\Program Files\Common Files\Symantec Shared
2014-07-11 16:23 - 2014-07-11 16:23 - 00000000 ____D () C:\Program Files (x86)\Norton 360
2014-07-11 16:15 - 2014-07-11 16:15 - 00000264 _____ () C:\Users\Moritz\Desktop\Cut the Rope.url
2014-07-11 16:14 - 2014-07-11 16:14 - 00000000 ____D () C:\ProgramData\PCSettings
2014-07-11 14:39 - 2014-07-11 14:30 - 00000000 ____D () C:\Program Files (x86)\PDF Architect 2
2014-07-11 14:33 - 2014-07-11 14:33 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\PDF Architect 2
2014-07-11 14:33 - 2014-07-11 14:28 - 00000000 ____D () C:\Program Files (x86)\PDFCreator
2014-07-11 14:30 - 2014-07-11 14:30 - 00001017 _____ () C:\Users\Public\Desktop\PDF Architect 2.lnk
2014-07-11 14:30 - 2014-07-11 14:30 - 00000000 ____D () C:\Users\Moritz\Documents\PDF Architect 2
2014-07-11 14:30 - 2014-07-11 14:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Architect 2
2014-07-11 14:28 - 2014-07-11 14:28 - 00001035 _____ () C:\Users\Public\Desktop\PDFCreator.lnk
2014-07-11 14:28 - 2014-07-11 14:28 - 00000000 ____D () C:\ProgramData\PDF Architect 2
2014-07-11 14:28 - 2014-07-11 14:28 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDFCreator
2014-07-11 14:26 - 2014-07-11 14:25 - 27843432 _____ (pdfforge ) C:\Users\Moritz\Downloads\PDFCreator-1_7_3_setup.exe
2014-07-10 16:58 - 2014-07-10 16:58 - 00000000 ____D () C:\Users\Moritz\AppData\Roaming\OpenOffice
2014-07-08 20:05 - 2014-05-01 00:48 - 00003772 _____ () C:\windows\System32\Tasks\Adobe Flash Player Updater
2014-07-08 11:05 - 2014-07-08 11:05 - 00001116 _____ () C:\Users\Public\Desktop\OpenOffice 4.1.0.lnk
2014-07-08 11:05 - 2014-07-08 11:05 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.0
2014-07-08 11:04 - 2014-07-08 11:04 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-07-08 10:48 - 2014-07-08 10:47 - 00961360 _____ (Chip Digital GmbH) C:\Users\Moritz\Downloads\OpenOffice - CHIP-Installer.exe
2014-07-07 17:04 - 2014-07-11 16:47 - 00057528 _____ (Corsica) C:\windows\system32\Drivers\webinstr.sys
2014-07-02 13:52 - 2014-07-02 12:51 - 00000000 ____D () C:\Users\Moritz\Desktop\uni
2014-07-01 00:42 - 2014-07-09 15:11 - 00702464 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2014-07-01 00:42 - 2014-07-09 15:11 - 00394240 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2014-07-01 00:42 - 2014-07-09 15:11 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2014-06-28 05:35 - 2014-07-09 15:11 - 00556544 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2014-06-26 22:53 - 2014-07-11 17:07 - 00703968 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2014-06-26 22:53 - 2014-07-11 17:07 - 00105440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-26 21:20 - 2014-06-26 21:20 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_wpdcomp_01_11_00.Wdf
2014-06-26 17:17 - 2014-06-26 17:17 - 00000000 ____H () C:\windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-06-26 09:49 - 2014-04-28 13:23 - 00000000 ____D () C:\Users\Moritz\Documents\Bluetooth Folder
2014-06-22 12:02 - 2014-06-22 12:02 - 00262144 _____ () C:\windows\Minidump\062214-10795-01.dmp
2014-06-20 11:02 - 2014-06-20 11:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-06-20 11:02 - 2014-06-20 11:02 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-06-20 11:02 - 2014-05-12 17:09 - 00001931 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-06-20 11:02 - 2014-05-12 17:09 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-06-19 04:12 - 2014-07-09 13:14 - 02239488 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-06-19 04:12 - 2014-07-09 13:14 - 01366528 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-06-19 04:12 - 2014-07-09 13:14 - 00915968 _____ (Microsoft Corporation) C:\windows\system32\uxtheme.dll
2014-06-19 04:12 - 2014-07-09 13:14 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\UXInit.dll
2014-06-19 04:12 - 2014-07-09 13:14 - 00051712 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-06-19 04:11 - 2014-07-09 13:14 - 19277312 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-06-19 04:11 - 2014-07-09 13:14 - 00197120 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-06-19 04:11 - 2014-07-09 13:14 - 00097792 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 15369728 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 03959296 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 02650624 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00855552 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00603136 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00452096 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00281600 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00255488 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00136704 _____ (Microsoft Corporation) C:\windows\system32\iesysprep.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00067072 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00053760 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-06-19 04:10 - 2014-07-09 13:14 - 00039936 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-06-19 04:09 - 2014-07-09 13:14 - 01508864 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-06-19 02:53 - 2014-07-09 13:14 - 14368768 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2014-06-19 02:53 - 2014-07-09 13:14 - 01766400 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2014-06-19 02:53 - 2014-07-09 13:14 - 01141760 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2014-06-19 02:53 - 2014-07-09 13:14 - 00493056 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2014-06-19 02:53 - 2014-07-09 13:14 - 00163840 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2014-06-19 02:53 - 2014-07-09 13:14 - 00080896 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2014-06-19 02:53 - 2014-07-09 13:14 - 00044032 _____ (Microsoft Corporation) C:\windows\SysWOW64\UXInit.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 13732352 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 02863616 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 02051072 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 01440768 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2014-06-19 02:52 - 2014-07-09 13:14 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 00357888 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 00226816 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 00109056 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesysprep.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 00061440 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 00039936 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2014-06-19 02:52 - 2014-07-09 13:14 - 00033280 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2014-06-19 02:33 - 2014-07-09 13:14 - 02706432 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-06-19 02:30 - 2014-07-09 13:14 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2014-06-19 00:05 - 2014-07-09 13:14 - 00534528 _____ (Microsoft Corporation) C:\windows\SysWOW64\uxtheme.dll
2014-06-18 11:19 - 2012-07-26 10:12 - 00000000 ____D () C:\windows\AUInstallAgent
2014-06-18 01:27 - 2014-07-09 13:15 - 01440256 _____ (Microsoft Corporation) C:\windows\SysWOW64\osk.exe
2014-06-18 01:24 - 2014-07-09 13:15 - 01557504 _____ (Microsoft Corporation) C:\windows\system32\osk.exe
2014-06-17 11:39 - 2014-04-28 13:35 - 00000000 ____D () C:\Users\Public\Downloads\Norton
Files to move or delete:
====================
C:\ProgramData\MakeMarkerFile.exe
C:\Users\EasySurvey\EasySurvey.exe
Some content of TEMP:
====================
C:\Users\Moritz\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-14 13:56
==================== End Of Log ============================ --- --- --- |