Fabienne98 | 15.07.2014 21:29 | Code:
# AdwCleaner v3.215 - Bericht erstellt am 15/07/2014 um 21:33:26
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 7 Ultimate Service Pack 1 (32 bits)
# Benutzername : Fabienne - FABIENNE-PC
# Gestartet von : D:\Downloads\adwcleaner_3.215.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : CltMngSvc
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\SearchProtect
Ordner Gelöscht : C:\Users\Fabienne\AppData\Local\b1e
Ordner Gelöscht : C:\Users\Fabienne\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\Fabienne\AppData\Local\Temp\OCS
Ordner Gelöscht : C:\Users\Fabienne\AppData\Roaming\B1Toolbar
Ordner Gelöscht : C:\Users\Fabienne\AppData\Roaming\OpenCandy
Ordner Gelöscht : C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\hahpjplbmicfkmoccokbjejahjjpnena
Datei Gelöscht : C:\END
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKCU\Software\Google\Chrome\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1EC9510D-A439-4950-9399-B6399EDF9EA7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\DivX\Install\Setup\WizardLayout\ConduitToolbar
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~1\SEARCH~1\SEARCH~1\bin\SPVC32~1.DLL
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAFFABD88-BD60-452D-BEF6-70DF323595FD&SearchSource=58&CUI=&UM=5&UP=&q={searchTerms}&SSPV=
Gelöscht [Homepage] : hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAFFABD88-BD60-452D-BEF6-70DF323595FD&SearchSource=55&CUI=&UM=5&UP=&SSPV=
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : bopakagnckmlgajfccecajhnimjiiedh
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : hahpjplbmicfkmoccokbjejahjjpnena
*************************
AdwCleaner[R0].txt - [3765 octets] - [15/07/2014 21:32:48]
AdwCleaner[S0].txt - [3515 octets] - [15/07/2014 21:33:26]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3575 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Ultimate x86
Ran by Fabienne on 15.07.2014 at 21:45:14,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\Users\Fabienne\appdata\locallow\boost_interprocess"
Successfully deleted: [Folder] "C:\Windows\system32\ai_recyclebin"
~~~ Chrome
Successfully deleted: [Folder] C:\Users\Fabienne\appdata\local\Google\Chrome\User Data\Default\Extensions\hahpjplbmicfkmoccokbjejahjjpnena
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 15.07.2014 at 21:47:30,57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 15.07.2014
Scan Time: 21:53:36
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.2.1012
Malware Database: v2014.07.15.13
Rootkit Database: v2014.07.14.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Fabienne
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 253114
Time Elapsed: 9 min, 17 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 10
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3288691, Quarantined, [d207bee1b5c6ef4758176c34f111629e],
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3297265, Quarantined, [36a3bde24d2e3cfa7af5d0d0b84acf31],
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3297861, Quarantined, [f8e10c93661515211c532779de242ad6],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\SearchProtect, Quarantined, [08d18619fd7ef2446e685461e31f01ff],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\SearchProtect\SearchProtect, Quarantined, [08d18619fd7ef2446e685461e31f01ff],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\SearchProtect\SearchProtect\rep, Quarantined, [08d18619fd7ef2446e685461e31f01ff],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\SearchProtect\UI, Quarantined, [08d18619fd7ef2446e685461e31f01ff],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\SearchProtect\UI\rep, Quarantined, [08d18619fd7ef2446e685461e31f01ff],
PUP.Optional.Extutil.A, C:\Users\Fabienne\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B, Quarantined, [fcddfea15328da5c1c1d9e1a986af20e],
PUP.Optional.Managera.A, C:\Users\Fabienne\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42, Quarantined, [30a95d42314ae551bf7bfdbb1de59d63],
Files: 17
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\Temp\nsw5771.tmp, Quarantined, [b722acf3e9922f0714a3d4bfdb262cd4],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\Temp\SPSetup.exe, Quarantined, [eaef910ea2d9c47200b79ff4e71a03fd],
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3297265\ism.exe, Quarantined, [8c4d4d527ffc52e49b61206e9f62ac54],
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3288691\chromeid.txt, Quarantined, [d207bee1b5c6ef4758176c34f111629e],
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3288691\setup.ini.txt, Quarantined, [d207bee1b5c6ef4758176c34f111629e],
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3297861\chromeid.txt, Quarantined, [f8e10c93661515211c532779de242ad6],
PUP.Optional.Conduit.A, C:\Users\Fabienne\AppData\Local\Temp\ct3297861\setup.ini.txt, Quarantined, [f8e10c93661515211c532779de242ad6],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, Quarantined, [08d18619fd7ef2446e685461e31f01ff],
PUP.Optional.SearchProtect.A, C:\Users\Fabienne\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, Quarantined, [08d18619fd7ef2446e685461e31f01ff],
PUP.Optional.Extutil.A, C:\Users\Fabienne\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\bk.js, Quarantined, [fcddfea15328da5c1c1d9e1a986af20e],
PUP.Optional.Extutil.A, C:\Users\Fabienne\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\cs.js, Quarantined, [fcddfea15328da5c1c1d9e1a986af20e],
PUP.Optional.Extutil.A, C:\Users\Fabienne\AppData\Local\Temp\D7ADFCCA-EE7E-442C-9999-C4D14FEF360B\manifest.json, Quarantined, [fcddfea15328da5c1c1d9e1a986af20e],
PUP.Optional.Managera.A, C:\Users\Fabienne\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\cs.js, Quarantined, [30a95d42314ae551bf7bfdbb1de59d63],
PUP.Optional.Managera.A, C:\Users\Fabienne\AppData\Local\Temp\38fdaae5-8e0e-493c-88ec-e05c3be06e42\manifest.json, Quarantined, [30a95d42314ae551bf7bfdbb1de59d63],
PUP.Optional.Trovi, C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "search_url": "hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAFFABD88-BD60-452D-BEF6-70DF323595FD&SearchSource=58&CUI=&UM=5&UP=&q={searchTerms}&SSPV=",), Replaced,[d6030b94304b65d13826f5dbbe466c94]
PUP.Optional.Conduit, C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "suggest_url": "hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}",), Replaced,[6772930cb5c63afca9b64e8217ed4fb1]
PUP.Optional.Trovi.A, C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Preferences, Good: (), Bad: ( "homepage": "hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAFFABD88-BD60-452D-BEF6-70DF323595FD&SearchSource=55&CUI=&UM=5&UP=&SSPV=",), Replaced,[7960603fe39853e3fef8e7e97193847c]
Physical Sectors: 0
(No malicious items detected)
(end)
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:15-07-2014 01
Ran by Fabienne (administrator) on FABIENNE-PC on 15-07-2014 22:28:15
Running from D:\Dokumente
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Egis Technology Inc. ) C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe
(Egis Technology Inc. ) C:\Program Files\EgisTec BioExcess\EgisService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Windows\System32\IgrsSvcs.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtLED\RtLEDService.exe
(Realtek Semiconductor Corp.) C:\Program Files\Realtek\RtLED\RtLED.exe
(Lenovo.) C:\Windows\System32\TPHDEXLG.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation.) C:\Program Files\Microsoft\BingBar\7.1.362.0\SeaPort.EXE
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Lenovo(beijing) Limited) C:\Program Files\Lenovo\Energy Management\utility.exe
(Lenovo (Beijing) Limited) C:\Program Files\Lenovo\Energy Management\Energy Management.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Vimicro) C:\Program Files\USB Camera\VM331_STI.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(CyberLink Corp.) C:\Program Files\Lenovo\YouCam\YouCamTray.exe
() C:\Program Files\DivX\DivX Update\DivXUpdate.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files\OpenOffice.org 3\program\soffice.bin
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Egis Technology Inc. ) C:\Program Files\EgisTec BioExcess\EgisTSR.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Skype Technologies) C:\Program Files\Skype\Updater\Updater.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [951576 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [EnergyUtility] => C:\Program Files\Lenovo\Energy Management\utility.exe [4204448 2010-04-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [Energy Management] => C:\Program Files\Lenovo\Energy Management\Energy Management.exe [6285216 2010-03-18] (Lenovo (Beijing) Limited)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [9222760 2010-06-02] (Realtek Semiconductor)
HKLM\...\Run: [EgisTecPMMUpdate] => C:\Program Files\EgisTec IPS\PmmUpdate.exe [407920 2010-11-05] (Egis Technology Inc.)
HKLM\...\Run: [EgisUpdate] => C:\Program Files\EgisTec IPS\EgisUpdate.exe [202096 2010-11-05] (Egis Technology Inc.)
HKLM\...\Run: [VitaKeyTSR] => C:\Program Files\EgisTec BioExcess\EgisTSR.exe [383568 2012-06-17] (Egis Technology Inc. )
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [1822600 2010-03-29] (ELAN Microelectronics Corp.)
HKLM\...\Run: [331BigDog] => C:\Program Files\USB Camera\VM331_STI.EXE [536576 2010-01-15] (Vimicro)
HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [186272 2010-03-15] (Lenovo.)
HKLM\...\Run: [IMSS] => C:\Program Files\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111640 2009-09-30] ()
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [UCam_Menu] => C:\Program Files\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [YouCam Mirror Tray icon] => C:\Program Files\Lenovo\YouCam\YouCamTray.exe [171104 2010-03-02] (CyberLink Corp.)
HKLM\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2013-05-20] (DivX, LLC)
HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1263952 2013-02-13] ()
HKU\S-1-5-21-2075962482-3085193338-3852838679-1000\...\Run: [81D1B28E2FB7D0F4B6DDE1BD156F1A528F4F2457._service_run] => "C:\Users\Fabienne\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
Lsa: [Notification Packages] scecli EgisPwdFilter EgisDSPwdFilter
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\Users\Fabienne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
SearchScopes: HKLM - DefaultScope value is missing.
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO: DivX Plus Web Player HTML5 <video> -> {326E768D-4182-46FD-9C16-1449A49795F4} -> C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
BHO: EgisPBIE Class -> {7B51CCBE-4AF9-44A6-BDAB-D7F7E4C4E6F9} -> C:\Program Files\EgisTec BioExcess\EgisPBIE.dll (Egis Technology Inc.)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF Plugin: @divx.com/DivX Plus Web Player Plug-In,version=1.0.0 - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.1 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Fabienne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files\EgisTec BioExcess\FFExt
FF Extension: Online Accounts Extension - C:\Program Files\EgisTec BioExcess\FFExt [2012-12-14]
FF HKLM\...\Firefox\Extensions: [{23fcfd51-4958-4f00-80a3-ae97e717ed8b}] - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5
FF Extension: DivX Plus Web Player HTML5 <video> - C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2013-08-20]
FF HKCU\...\Firefox\Extensions: [{B64D9B05-48E1-4CEB-BF58-E0643994E900}] - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff
FF Extension: Download videos and MP3s from YouTube - C:\Program Files\Common Files\DVDVideoSoft\plugins\ff [2014-06-30]
Chrome:
=======
CHR HomePage: hxxp://www.trovi.com/?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAFFABD88-BD60-452D-BEF6-70DF323595FD&SearchSource=55&CUI=&UM=5&UP=&SSPV=
CHR StartupUrls: "hxxp://www.google.de/"
CHR DefaultSearchKeyword: trovi.search
CHR DefaultSearchProvider: Trovi search
CHR DefaultSearchURL: hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3325585&octid=EB_ORIGINAL_CTID&ISID=MAFFABD88-BD60-452D-BEF6-70DF323595FD&SearchSource=58&CUI=&UM=5&UP=&q={searchTerms}&SSPV=
CHR DefaultNewTabURL:
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\35.0.1916.153\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\35.0.1916.153\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\35.0.1916.153\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (DivX VOD Helper Plug-in) - C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
CHR Plugin: (DivX Plus Web Player) - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 7 U9) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.90.5) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll No File
CHR Extension: (hxxp://de.wikipedia.org/wiki/Wikipedia:Haupts) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\apmapjemmlbhjmfdcopphjflaeihceok [2012-12-16]
CHR Extension: (YouTube) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-12-14]
CHR Extension: (Adblock Plus) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2012-12-14]
CHR Extension: (Google-Suche) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-12-14]
CHR Extension: (hxxp://www.gutefrage.net/) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfgecohdgoijeaanoegifofmlkkbamnh [2012-12-30]
CHR Extension: (FlashFree) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebmieckllmmifjjbipnppinpiohpfahm [2012-12-14]
CHR Extension: (hxxp://translate.google.de/?hl=de) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\foiejfepgboncngaohkkhfhbkllkggok [2012-12-30]
CHR Extension: (AdBlock) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2012-12-14]
CHR Extension: (M82 Starburst Galaxy Theme) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlakjamlkeaadnjhokgmjcjgmmofndjl [2013-07-30]
CHR Extension: (Google Wallet) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-01]
CHR Extension: (Mehr Leistung und Videoformate für dein HTML5 <video>) - C:\Users\Fabienne\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm [2012-12-14]
CHR HKLM\...\Chrome\Extension: [nneajnkjbffgblleaoojgaacokifdkhm] - C:\Program Files\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx [2013-07-26]
========================== Services (Whitelisted) =================
R2 EgisTec Service; C:\Program Files\EgisTec BioExcess\EgisService.exe [704080 2012-06-17] (Egis Technology Inc. )
R2 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [650320 2012-06-17] (Egis Technology Inc. )
R2 IGRS; C:\Program Files\Lenovo\ReadyComm\common\IGRS.exe [38152 2009-07-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm AppSvc; C:\Program Files\Lenovo\ReadyComm\AppSvc.exe [509192 2009-08-14] (Lenovo Group Limited)
S3 Lenovo ReadyComm ConnSvc; C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe [579400 2009-09-22] (Lenovo Group Limited)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [235696 2014-04-09] (McAfee, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2014-03-11] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [279776 2014-03-11] (Microsoft Corporation)
S3 PS_MDP; C:\Program Files\Lenovo\ReadyComm\PS_MDP.dll [276296 2009-07-16] (Lenovo Group Limited)
R2 ReadyComm.DirectRouter; C:\Program Files\Lenovo\ReadyComm\common\router.dll [103688 2009-07-14] (Lenovo Group Limited)
R2 RtLedService; C:\Program Files\Realtek\RtLED\RtLEDService.exe [311296 2010-02-05] (Realtek Semiconductor Corp.) [File not signed]
S2 TuneUp.UtilitiesSvc; "C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe" [X]
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\Windows\System32\DRIVERS\AcpiVpc.sys [23136 2010-01-20] (Lenovo Corporation)
S3 Bridge0; C:\Windows\System32\drivers\WDBridge.sys [63240 2009-07-28] (Lenovo)
R3 ETD; C:\Windows\System32\DRIVERS\ETD.sys [131072 2010-03-26] (ELAN Microelectronics Corp.)
R2 FPSensor; C:\Windows\System32\Drivers\FPSensor.sys [29232 2012-12-14] (EgisTec)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.)
R0 LHDmgr; C:\Windows\System32\DRIVERS\LhdX86.sys [32352 2010-01-15] (Lenovo.)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-07-15] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [231960 2014-01-25] (Microsoft Corporation)
R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [19304 2012-12-14] (Egis Technology Inc.)
R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16744 2012-12-14] (Egis Technology Inc.)
R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [62048 2012-12-14] (Egis Technology Inc.)
R3 vm331avs; C:\Windows\System32\Drivers\vm331avs.sys [185344 2010-01-27] (Vimicro Corporation)
R3 wdmirror; C:\Windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\Windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
S1 MpKslb93d74c9; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1CC46727-EFF3-4504-B936-2DF1DC6C92F2}\MpKslb93d74c9.sys [X]
S1 MpKsle35a44bc; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1CC46727-EFF3-4504-B936-2DF1DC6C92F2}\MpKsle35a44bc.sys [X]
S1 MpKslf4e120cf; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1CC46727-EFF3-4504-B936-2DF1DC6C92F2}\MpKslf4e120cf.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 TuneUpUtilitiesDrv; \??\C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-07-15 22:21 - 2014-07-15 22:21 - 00005334 _____ () C:\Users\Fabienne\Desktop\mbam.txt
2014-07-15 21:52 - 2014-07-15 22:16 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-15 21:51 - 2014-07-15 21:51 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-15 21:51 - 2014-07-15 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-15 21:51 - 2014-07-15 21:51 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-15 21:51 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-15 21:51 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-15 21:51 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-07-15 21:47 - 2014-07-15 21:47 - 00000942 _____ () C:\Users\Fabienne\Downloads\JRT.txt
2014-07-15 21:45 - 2014-07-15 21:45 - 00000000 ____D () C:\Windows\ERUNT
2014-07-15 21:33 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll
2014-07-15 21:32 - 2014-07-15 21:33 - 00000000 ____D () C:\AdwCleaner
2014-07-15 21:17 - 2014-07-15 21:17 - 00001226 _____ () C:\Users\Fabienne\Desktop\Revo Uninstaller.lnk
2014-07-15 21:17 - 2014-07-15 21:17 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-15 12:19 - 2014-07-15 22:28 - 00000000 ____D () C:\FRST
2014-07-10 12:13 - 2014-06-30 03:40 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-07-10 12:13 - 2014-06-30 03:36 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-07-10 12:13 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 12:13 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 12:13 - 2014-06-19 01:56 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 12:13 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 12:13 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 12:13 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 12:13 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 12:13 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 12:13 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 12:13 - 2014-06-19 01:23 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 12:13 - 2014-06-19 01:16 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 12:13 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 12:13 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 12:13 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 12:13 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 12:13 - 2014-06-19 00:52 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 12:13 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 12:13 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 12:13 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 12:13 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 12:13 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 12:13 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 12:13 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 12:13 - 2014-06-18 02:52 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 12:12 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 12:12 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 12:12 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 12:12 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 12:12 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 12:12 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 12:12 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 12:12 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 12:07 - 2014-06-06 11:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-07-10 12:07 - 2014-05-30 09:52 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-07-10 12:07 - 2014-05-30 09:52 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-07-10 12:07 - 2014-05-30 09:52 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-07-10 12:07 - 2014-05-30 09:52 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-07-10 12:07 - 2014-05-30 09:52 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-07-10 12:07 - 2014-05-30 09:52 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-07-10 12:07 - 2014-05-30 09:52 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-07-10 12:07 - 2014-05-30 08:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-07-10 12:02 - 2014-06-05 16:26 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-08 15:53 - 2014-07-08 15:53 - 00000000 ____D () C:\Users\Fabienne\AppData\Local\Unity
2014-07-08 15:47 - 2014-07-08 15:47 - 00135216 _____ () C:\Windows\Minidump\070814-36785-01.dmp
2014-07-08 15:47 - 2014-07-08 15:47 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-07-08 15:30 - 2014-07-08 15:30 - 00000000 ____D () C:\Users\Fabienne\AppData\Roaming\Unity
2014-07-05 19:30 - 2014-07-08 16:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-07-05 19:30 - 2014-07-08 16:45 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-07-02 20:49 - 2014-07-02 20:49 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-06-30 15:59 - 2014-03-20 14:44 - 00036664 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2014-06-30 15:59 - 2014-03-20 14:44 - 00025400 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2014-06-30 15:57 - 2014-06-30 15:57 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-06-30 15:51 - 2014-06-30 15:51 - 00000000 __SHD () C:\Users\Fabienne\AppData\Local\EmieUserList
2014-06-30 15:51 - 2014-06-30 15:51 - 00000000 __SHD () C:\Users\Fabienne\AppData\Local\EmieSiteList
2014-06-30 15:46 - 2014-06-30 15:47 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2014-06-30 15:46 - 2014-06-30 15:46 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-06-30 15:45 - 2014-06-30 15:49 - 00000000 ____D () C:\Users\Fabienne\AppData\Roaming\DVDVideoSoft
2014-06-29 17:21 - 2014-06-29 18:03 - 00032751 _____ () C:\Users\Fabienne\Documents\Dänische Flagge.odt
2014-06-29 16:24 - 2014-07-08 16:46 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-06-29 16:24 - 2014-06-29 16:24 - 00000000 ____D () C:\ProgramData\McAfee
==================== One Month Modified Files and Folders =======
2014-07-15 22:28 - 2014-07-15 12:19 - 00000000 ____D () C:\FRST
2014-07-15 22:28 - 2012-11-10 18:01 - 00000000 ____D () C:\Users\Fabienne\AppData\Roaming\Skype
2014-07-15 22:26 - 2012-12-14 01:01 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-15 22:21 - 2014-07-15 22:21 - 00005334 _____ () C:\Users\Fabienne\Desktop\mbam.txt
2014-07-15 22:16 - 2014-07-15 21:52 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-15 22:16 - 2012-12-14 01:01 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-15 22:10 - 2009-07-14 06:34 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-15 22:10 - 2009-07-14 06:34 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-15 22:09 - 2012-11-09 16:26 - 01290685 _____ () C:\Windows\WindowsUpdate.log
2014-07-15 22:09 - 2009-11-10 20:44 - 01619700 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-15 22:04 - 2013-08-13 22:33 - 00021194 _____ () C:\Windows\setupact.log
2014-07-15 22:04 - 2012-11-10 14:50 - 00093474 _____ () C:\Windows\PFRO.log
2014-07-15 22:04 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-15 21:51 - 2014-07-15 21:51 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-15 21:51 - 2014-07-15 21:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-15 21:51 - 2014-07-15 21:51 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-07-15 21:51 - 2012-11-10 19:01 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-15 21:47 - 2014-07-15 21:47 - 00000942 _____ () C:\Users\Fabienne\Downloads\JRT.txt
2014-07-15 21:45 - 2014-07-15 21:45 - 00000000 ____D () C:\Windows\ERUNT
2014-07-15 21:33 - 2014-07-15 21:32 - 00000000 ____D () C:\AdwCleaner
2014-07-15 21:32 - 2012-11-10 19:41 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-15 21:17 - 2014-07-15 21:17 - 00001226 _____ () C:\Users\Fabienne\Desktop\Revo Uninstaller.lnk
2014-07-15 21:17 - 2014-07-15 21:17 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-07-15 20:55 - 2013-12-26 14:36 - 00000000 ____D () C:\Program Files\Steam
2014-07-15 20:00 - 2013-12-26 14:36 - 00000000 ____D () C:\Program Files\Common Files\Steam
2014-07-15 15:05 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-07-13 13:35 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-11 23:26 - 2009-07-14 06:33 - 00312504 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-11 23:24 - 2014-05-05 14:49 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-07-11 23:24 - 2009-07-14 10:56 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-11 23:24 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-07-11 19:06 - 2013-07-25 19:01 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-11 19:03 - 2009-10-14 04:21 - 93585272 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-09 16:32 - 2013-02-26 20:33 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerInstaller.exe
2014-07-09 16:32 - 2012-11-10 19:41 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-07-09 16:32 - 2012-11-10 19:41 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-07-08 16:46 - 2014-07-05 19:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2014-07-08 16:46 - 2014-06-29 16:24 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-07-08 16:46 - 2012-12-14 00:15 - 00000000 ____D () C:\Users\Fabienne\AppData\Local\BioExcess
2014-07-08 16:46 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\wfp
2014-07-08 16:45 - 2014-07-05 19:30 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-07-08 16:45 - 2009-07-14 10:56 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-07-08 16:45 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\registration
2014-07-08 15:53 - 2014-07-08 15:53 - 00000000 ____D () C:\Users\Fabienne\AppData\Local\Unity
2014-07-08 15:47 - 2014-07-08 15:47 - 00135216 _____ () C:\Windows\Minidump\070814-36785-01.dmp
2014-07-08 15:47 - 2014-07-08 15:47 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-07-08 15:47 - 2013-09-12 16:28 - 176007817 _____ () C:\Windows\MEMORY.DMP
2014-07-08 15:47 - 2013-02-26 20:13 - 00000000 ____D () C:\Windows\Minidump
2014-07-08 15:47 - 2012-11-09 16:30 - 00000000 ____D () C:\Users\Fabienne
2014-07-08 15:30 - 2014-07-08 15:30 - 00000000 ____D () C:\Users\Fabienne\AppData\Roaming\Unity
2014-07-02 20:50 - 2012-11-10 18:00 - 00000000 ____D () C:\ProgramData\Skype
2014-07-02 20:49 - 2014-07-02 20:49 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-07-02 20:49 - 2014-03-28 22:56 - 00000000 ___RD () C:\Program Files\Skype
2014-06-30 15:57 - 2014-06-30 15:57 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-06-30 15:51 - 2014-06-30 15:51 - 00000000 __SHD () C:\Users\Fabienne\AppData\Local\EmieUserList
2014-06-30 15:51 - 2014-06-30 15:51 - 00000000 __SHD () C:\Users\Fabienne\AppData\Local\EmieSiteList
2014-06-30 15:49 - 2014-06-30 15:45 - 00000000 ____D () C:\Users\Fabienne\AppData\Roaming\DVDVideoSoft
2014-06-30 15:47 - 2014-06-30 15:46 - 00000000 ____D () C:\Program Files\DVDVideoSoft
2014-06-30 15:46 - 2014-06-30 15:46 - 00000000 ____D () C:\Program Files\Common Files\DVDVideoSoft
2014-06-30 03:40 - 2014-07-10 12:13 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-30 03:36 - 2014-07-10 12:13 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-29 18:03 - 2014-06-29 17:21 - 00032751 _____ () C:\Users\Fabienne\Documents\Dänische Flagge.odt
2014-06-29 16:24 - 2014-06-29 16:24 - 00000000 ____D () C:\ProgramData\McAfee
2014-06-25 18:11 - 2014-05-27 08:49 - 00000000 ____D () C:\Users\Fabienne\AppData\Roaming\TS3Client
2014-06-20 21:39 - 2014-07-10 12:13 - 00240824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-19 02:16 - 2014-07-10 12:12 - 17276416 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 01:56 - 2014-07-10 12:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 01:56 - 2014-07-10 12:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-19 01:38 - 2014-07-10 12:12 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-19 01:37 - 2014-07-10 12:13 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 01:36 - 2014-07-10 12:13 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-19 01:35 - 2014-07-10 12:12 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-19 01:32 - 2014-07-10 12:12 - 02179072 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 01:28 - 2014-07-10 12:13 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 01:28 - 2014-07-10 12:13 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 01:25 - 2014-07-10 12:13 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-19 01:23 - 2014-07-10 12:13 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-19 01:23 - 2014-07-10 12:13 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-19 01:22 - 2014-07-10 12:12 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-19 01:16 - 2014-07-10 12:13 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-19 01:12 - 2014-07-10 12:13 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 01:06 - 2014-07-10 12:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 01:01 - 2014-07-10 12:13 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-19 00:59 - 2014-07-10 12:12 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-19 00:58 - 2014-07-10 12:13 - 00239616 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-19 00:52 - 2014-07-10 12:13 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-19 00:52 - 2014-07-10 12:12 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-19 00:49 - 2014-07-10 12:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-19 00:46 - 2014-07-10 12:12 - 01068032 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-19 00:45 - 2014-07-10 12:13 - 01964544 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-19 00:35 - 2014-07-10 12:13 - 11742208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-19 00:13 - 2014-07-10 12:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-19 00:09 - 2014-07-10 12:13 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-19 00:07 - 2014-07-10 12:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-18 03:51 - 2014-07-10 12:13 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-18 02:52 - 2014-07-10 12:13 - 02350080 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
Some content of TEMP:
====================
C:\Users\Fabienne\AppData\Local\Temp\BingBarSetup-Partner.exe
C:\Users\Fabienne\AppData\Local\Temp\DivXSetup.exe
C:\Users\Fabienne\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-15 14:56
==================== End Of Log ============================ --- --- ---
--- --- --- |