|   | mami0106 | 21.01.2015 15:12 |  
 Okay, alles gemacht. Hier die Logs: 
mbam   Code: 
 Malwarebytes Anti-Malwarewww.malwarebytes.org
 
 Suchlauf Datum: 21.01.2015
 Suchlauf-Zeit: 14:11:52
 Logdatei: mbam.txt
 Administrator: Ja
 
 Version: 2.00.4.1028
 Malware Datenbank: v2015.01.21.06
 Rootkit Datenbank: v2015.01.14.01
 Lizenz: Kostenlos
 Malware Schutz: Deaktiviert
 Bösartiger Webseiten Schutz: Deaktiviert
 Selbstschutz: Deaktiviert
 
 Betriebssystem: Windows 8.1
 CPU: x64
 Dateisystem: NTFS
 Benutzer: Carolin
 
 Suchlauf-Art: Bedrohungs-Suchlauf
 Ergebnis: Abgeschlossen
 Durchsuchte Objekte: 389511
 Verstrichene Zeit: 21 Min, 8 Sek
 
 Speicher: Aktiviert
 Autostart: Aktiviert
 Dateisystem: Aktiviert
 Archive: Aktiviert
 Rootkits: Deaktiviert
 Heuristik: Aktiviert
 PUP: Aktiviert
 PUM: Aktiviert
 
 Prozesse: 1
 PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\aPtfNhADkd.exe, 2828, Löschen bei Neustart, [9971b347b6d3e254fcb6e5c6ad54d927]
 
 Module: 0
 (Keine schädliche Elemente erkannt)
 
 Registrierungsschlüssel: 10
 PUP.Optional.SafeWeb.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\aPtfNhADkd, In Quarantäne, [9971b347b6d3e254fcb6e5c6ad54d927],
 PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [a86227d32069af87e5e4fcf8ed1551af],
 PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [a86227d32069af87e5e4fcf8ed1551af],
 PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [4bbf19e12c5d39fd079143b18d7524dc],
 PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [4bbf19e12c5d39fd079143b18d7524dc],
 PUP.Optional.SearchProtect.A, HKU\S-1-5-21-599079236-3312268694-3269153300-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [35d523d7b8d177bf8f2005ea11f13ec2],
 PUP.Optional.SafeWeb.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SafeWeb, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
 PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [cc3ec337ddac2313a8f06194e123e51b],
 PUP.Optional.Softonic.A, HKU\S-1-5-21-599079236-3312268694-3269153300-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [000a35c58cfdaf87798dec8fa3602ad6],
 PUP.Optional.MultiIE.A, HKU\S-1-5-21-599079236-3312268694-3269153300-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, In Quarantäne, [d139e8126e1b0531dd00f7f712f2857b],
 
 Registrierungswerte: 1
 PUP.Optional.SafeWeb, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SAFEWEB|HelpLink, hxxp://www.safewebonline.com/about.html, In Quarantäne, [2cdeab4f0c7d4aec52a78f0449bac13f]
 
 Registrierungsdaten: 0
 (Keine schädliche Elemente erkannt)
 
 Ordner: 23
 PUP.Optional.SafeWeb.A, C:\Users\Carolin\AppData\Local\SafeWeb, In Quarantäne, [e723f9010d7c63d38b202f6c07fc7789],
 PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.OpenCandy, C:\Users\Carolin\AppData\Roaming\OpenCandy, In Quarantäne, [fa10d92198f1092dde129aa22ed518e8],
 PUP.Optional.OpenCandy, C:\Users\Carolin\AppData\Roaming\OpenCandy\1E9F9EE191CA4DF7B10B9C39B1EDAC99, In Quarantäne, [fa10d92198f1092dde129aa22ed518e8],
 PUP.Optional.SearchProtect.A, C:\Users\Carolin\AppData\Local\SearchProtect, In Quarantäne, [44c615e54346290d421590c216edf010],
 
 Dateien: 89
 PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\aPtfNhADkd.exe, Löschen bei Neustart, [9971b347b6d3e254fcb6e5c6ad54d927],
 PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\dat\cbwvsh.exe, Löschen bei Neustart, [58b2a1590d7c0c2a189a7e2dfc055da3],
 PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\dat\PxEXsGQptN.exe, Löschen bei Neustart, [f6147288bccd3ff7aa085a5126dbcc34],
 PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Roaming\OpenCandy\1E9F9EE191CA4DF7B10B9C39B1EDAC99\sp-downloader.exe, In Quarantäne, [b15977836a1f290d16e377c8a06155ab],
 PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nst23AF.exe, In Quarantäne, [5caeb5459beea195dd3d6e382fd2c33d],
 PUP.Optional.SafeWeb.A, C:\Users\Carolin\AppData\Local\Temp\Setup-2-.exe, In Quarantäne, [a86274863f4aca6c4a3d9fc546ba6b95],
 PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nsb28B2.exe, In Quarantäne, [13f719e15e2b87af74a6adf9758cd52b],
 PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nsdD54D.exe, In Quarantäne, [38d2ae4c147595a176a4b6f042bf03fd],
 PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nseD945.exe, In Quarantäne, [f713d3274940a98deb2ffbab08f9ec14],
 PUP.Optional.SearchProtect.A, C:\Users\Carolin\AppData\Local\Temp\nsvA94A.tmp, In Quarantäne, [3dcde911a9e0e551b0885d53e819ac54],
 PUP.Optional.Softonic, C:\Users\Carolin\Downloads\SoftonicDownloader_fuer_gamespy-arcade.exe, In Quarantäne, [42c8a258b5d474c2931d0c4e49b7748c],
 PUP.Optional.OpenCandy, C:\Users\Carolin\Downloads\DTLite4491-0356.exe, In Quarantäne, [b9518c6e9beec86e57e014b1af569967],
 PUP.Optional.SearchProtect, C:\Windows\apppatch\apppatch64\VCLdr64.dll, In Quarantäne, [c54503f7c3c64bebdaa484900df58080],
 PUP.Optional.SafeWeb.A, C:\Users\Carolin\AppData\Local\SafeWeb\data2.dat, In Quarantäne, [e723f9010d7c63d38b202f6c07fc7789],
 PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\app.dat, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
 PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\data.dat, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
 PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\SafeWeb.ico, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
 PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\Uninstall.exe, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
 PUP.Optional.Trovi.A, C:\Users\Carolin\AppData\Roaming\Mozilla\Firefox\Profiles\s8591zzg.default\searchplugins\trovi-search.xml, In Quarantäne, [6d9ded0dea9f6fc7409a5c47d52e0af6],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def-grey.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-dia.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Icon.ico, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\SP_DialogBG.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\DialogAPI.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
 PUP.Optional.SearchProtect, C:\Windows\apppatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [1feb23d7f79258de9a02a154e123c13f],
 
 Physische Sektoren: 0
 (Keine schädliche Elemente erkannt)
 
 
 (end)
 adwcleaner   Code: 
 # AdwCleaner v4.108 - Bericht erstellt am 21/01/2015 um 14:55:11# Aktualisiert 17/01/2015 von Xplode
 # Database : 2015-01-18.1 [Live]
 # Betriebssystem : Windows 8.1  (64 bits)
 # Benutzername : Carolin - JOSHI
 # Gestartet von : C:\Users\Carolin\Downloads\AdwCleaner_4.108.exe
 # Option : Löschen
 
 ***** [ Dienste ] *****
 
 
 ***** [ Dateien / Ordner ] *****
 
 Ordner Gelöscht : C:\ProgramData\Browser
 Datei Gelöscht : C:\Users\Carolin\Desktop\Continue Live Installation.lnk
 
 ***** [ Tasks ] *****
 
 Task Gelöscht : DriverEasy Scheduled Scan
 
 ***** [ Verknüpfungen ] *****
 
 
 ***** [ Registrierungsdatenbank ] *****
 
 Schlüssel Gelöscht : HKCU\Software\Classes\pokki
 Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
 Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
 Schlüssel Gelöscht : HKCU\Software\Pokki
 Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
 Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
 Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
 
 ***** [ Browser ] *****
 
 -\\ Internet Explorer v11.0.9600.17416
 
 
 -\\ Mozilla Firefox v35.0 (x86 de)
 
 
 *************************
 
 AdwCleaner[R0].txt - [2247 octets] - [21/01/2015 14:53:04]
 AdwCleaner[S0].txt - [1748 octets] - [21/01/2015 14:55:11]
 
 ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1808 octets] ##########
 jrt   Code: 
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Junkware Removal Tool (JRT) by Thisisu
 Version: 6.4.1 (12.28.2014:1)
 OS: Windows 8.1 x64
 Ran by Carolin on 21.01.2015 at 15:01:46,11
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
 ~~~ Services
 
 
 
 ~~~ Registry Values
 
 Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
 
 
 
 ~~~ Registry Keys
 
 Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
 Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
 Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
 Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
 
 
 
 ~~~ Files
 
 
 
 ~~~ Folders
 
 
 
 ~~~ FireFox
 
 Emptied folder: C:\Users\Carolin\AppData\Roaming\mozilla\firefox\profiles\s8591zzg.default\minidumps [5 files]
 
 
 
 ~~~ Event Viewer Logs were cleared
 
 
 
 
 
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 Scan was completed on 21.01.2015 at 15:04:55,61
 End of JRT log
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 frst:  
FRST Logfile:  
FRST Logfile:   Code: 
 Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015Ran by Carolin (administrator) on JOSHI on 21-01-2015 15:06:25
 Running from C:\Users\Carolin\Downloads
 Loaded Profiles: Carolin (Available profiles: Carolin)
 Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
 Internet Explorer Version 11 (Default browser: FF)
 Boot Mode: Normal
 Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
 ==================== Processes (Whitelisted) =================
 
 (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
 (AMD) C:\Windows\System32\atiesrxx.exe
 (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
 (AMD) C:\Windows\System32\atieclxx.exe
 (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
 (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
 (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
 (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
 (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
 (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
 (Microsoft Corporation) C:\Windows\System32\dasHost.exe
 (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
 (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
 (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
 (arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
 (SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimServiceFactory.exe
 (Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
 (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
 (AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
 (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
 (Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
 () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
 (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
 (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
 (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
 (Intel Corporation) C:\Windows\System32\igfxtray.exe
 (Intel Corporation) C:\Windows\System32\hkcmd.exe
 (Intel Corporation) C:\Windows\System32\igfxsrvc.exe
 (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
 (Intel Corporation) C:\Windows\System32\igfxpers.exe
 (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
 (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
 (SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
 (Akamai Technologies, Inc.) C:\Users\Carolin\AppData\Local\Akamai\netsession_win.exe
 (SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimService.exe
 (Akamai Technologies, Inc.) C:\Users\Carolin\AppData\Local\Akamai\netsession_win.exe
 (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
 (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
 (Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
 (Intel Corporation) C:\Windows\System32\igfxext.exe
 (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
 (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
 (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
 (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
 (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
 (Thisisu) C:\Users\Carolin\Downloads\JRT.exe
 (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
 (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
 (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
 (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
 
 
 ==================== Registry (Whitelisted) ==================
 
 (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
 HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-22] (ELAN Microelectronics Corp.)
 HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated)
 HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor)
 HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
 HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.)
 HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
 HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-09] (AVAST Software)
 HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2014-11-19] (Cisco Systems, Inc.)
 Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
 HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications))
 HKLM\...\Policies\Explorer: [NoFolderOptions] 0
 HKLM\...\Policies\Explorer: [NoControlPanel] 0
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Run: [SlimCleaner Plus] => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe [26163008 2014-08-04] (SlimWare Utilities, Inc.)
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 12 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [1400224 2013-09-25] (Adobe Systems Incorporated)
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Carolin\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\RunOnce: [Application Restart #0] => C:\Users\Carolin\AppData\Local\Pokki\Engine\HostAppService.exe [7843656 2015-01-01] (Pokki)
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\MountPoints2: {49bde67e-2b06-11e4-be78-00059a3c7a00} - "E:\Setup.exe"
 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
 ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (No File)
 ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
 
 ==================== Internet (Whitelisted) ====================
 
 (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?q={searchTerms}
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?q={searchTerms}
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
 HKU\S-1-5-21-599079236-3312268694-3269153300-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
 SearchScopes: HKLM-x32 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
 SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
 SearchScopes: HKU\S-1-5-21-599079236-3312268694-3269153300-1001 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
 BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
 BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
 BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
 BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
 BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
 BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
 BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
 BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
 BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
 BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
 BHO-x32: Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm -> {DDA57003-0068-4ed2-9D32-4D1EC707D94D} -> C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
 Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
 Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
 Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
 Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
 Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
 Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
 Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
 
 FireFox:
 ========
 FF ProfilePath: C:\Users\Carolin\AppData\Roaming\Mozilla\Firefox\Profiles\s8591zzg.default
 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
 FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
 FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
 FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
 FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
 FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
 FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
 FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
 FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
 FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
 FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
 FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
 FF Extension: Adblock Plus - C:\Users\Carolin\AppData\Roaming\Mozilla\Firefox\Profiles\s8591zzg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-09-14]
 FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
 FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-10-09]
 FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
 FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-26]
 FF HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
 FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
 
 Chrome:
 =======
 CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-01-17]
 CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
 CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-01-17]
 CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-26]
 
 ==================== Services (Whitelisted) =================
 
 (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
 R2 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-25] (Adobe Systems Incorporated)
 R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider)
 R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-26] (AVAST Software)
 R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-26] (Avast Software)
 R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated)
 R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated)
 R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-20] (Intel Corporation)
 R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
 S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
 R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
 R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-06-18] (Acer Incorporate)
 R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [154320 2014-12-03] (McAfee, Inc.)
 S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4230016 2013-01-28] (Symantec Corporation)
 R2 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
 R2 SlimService; C:\Program Files\SlimCleaner Plus\SlimServiceFactory.exe [244544 2014-08-04] (SlimWare Utilities, Inc.)
 S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
 S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
 
 ==================== Drivers (Whitelisted) ====================
 
 (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
 R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.)
 R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-26] ()
 R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-26] (AVAST Software)
 R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-26] (AVAST Software)
 R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-26] ()
 R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-26] (AVAST Software)
 R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-26] (AVAST Software)
 R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-26] (AVAST Software)
 R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-26] ()
 R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
 R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
 S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
 R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-08-23] (Disc Soft Ltd)
 S3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
 S3 LGSUsbFilt; C:\Windows\system32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.)
 R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
 R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
 R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-07-19] (Corel Corporation)
 R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
 S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2014-09-03] ()
 U4 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-26] (Avast Software)
 S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-06-11] (Cisco Systems, Inc.)
 S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
 
 ==================== NetSvcs (Whitelisted) ===================
 
 (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
 ==================== One Month Created Files and Folders ========
 
 (If an entry is included in the fixlist, the file\folder will be moved.)
 
 2015-01-21 15:06 - 2015-01-21 15:06 - 00020133 _____ () C:\Users\Carolin\Downloads\FRST.txt
 2015-01-21 15:04 - 2015-01-21 15:04 - 00001475 _____ () C:\Users\Carolin\Desktop\JRT.txt
 2015-01-21 15:01 - 2015-01-21 15:01 - 00000000 ____D () C:\WINDOWS\ERUNT
 2015-01-21 14:53 - 2015-01-21 14:55 - 00000000 ____D () C:\AdwCleaner
 2015-01-21 14:51 - 2015-01-21 14:51 - 00019368 _____ () C:\Users\Carolin\Desktop\mbam.txt
 2015-01-21 14:11 - 2015-01-21 14:48 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
 2015-01-21 14:11 - 2015-01-21 14:11 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2015-01-21 14:11 - 2015-01-21 14:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
 2015-01-21 14:11 - 2015-01-21 14:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
 2015-01-21 14:11 - 2015-01-21 14:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
 2015-01-21 14:11 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
 2015-01-21 14:11 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
 2015-01-21 14:11 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
 2015-01-20 22:54 - 2015-01-20 22:54 - 02186752 _____ () C:\Users\Carolin\Downloads\AdwCleaner_4.108.exe
 2015-01-20 22:54 - 2015-01-20 22:54 - 01707939 _____ (Thisisu) C:\Users\Carolin\Downloads\JRT.exe
 2015-01-20 22:52 - 2015-01-20 22:52 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Carolin\Downloads\mbam-setup-2.0.4.1028.exe
 2015-01-20 22:46 - 2015-01-20 22:46 - 02785665 _____ (PortableApps.com) C:\Users\Carolin\Downloads\RevoUninstallerPortable_1.95_Rev_2.paf.exe
 2015-01-20 22:46 - 2015-01-20 22:46 - 00000000 ____D () C:\Users\Carolin\Downloads\RevoUninstallerPortable
 2015-01-20 22:40 - 2015-01-20 22:40 - 00001284 _____ () C:\Users\Carolin\Desktop\Revo Uninstaller.lnk
 2015-01-20 22:40 - 2015-01-20 22:40 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
 2015-01-20 22:39 - 2015-01-20 22:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Carolin\Downloads\revosetup95.exe
 2015-01-20 21:31 - 2015-01-20 21:31 - 00380416 _____ () C:\Users\Carolin\Downloads\Gmer-19357.exe
 2015-01-20 21:28 - 2015-01-21 15:06 - 00000000 ____D () C:\FRST
 2015-01-20 21:28 - 2015-01-20 21:28 - 02126848 _____ (Farbar) C:\Users\Carolin\Downloads\FRST64.exe
 2015-01-20 21:27 - 2015-01-20 21:27 - 00000168 _____ () C:\Users\Carolin\defogger_reenable
 2015-01-20 21:26 - 2015-01-20 21:26 - 00050477 _____ () C:\Users\Carolin\Downloads\Defogger.exe
 2015-01-20 14:09 - 2015-01-20 14:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
 2015-01-19 10:35 - 2015-01-19 10:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
 2015-01-17 19:49 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
 2015-01-17 19:49 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
 2015-01-17 19:49 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
 2015-01-17 19:49 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
 2015-01-17 19:49 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
 2015-01-17 19:49 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
 2015-01-17 19:49 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
 2015-01-17 19:49 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
 2015-01-17 19:49 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
 2015-01-17 19:49 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
 2015-01-17 19:49 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
 2015-01-17 19:49 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
 2015-01-17 19:49 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
 2015-01-17 19:49 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
 2015-01-17 19:49 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
 2015-01-17 19:49 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
 2015-01-17 19:49 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
 2015-01-17 19:49 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
 2015-01-17 19:49 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
 2015-01-17 19:49 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
 2015-01-17 19:49 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
 2015-01-17 19:49 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
 2015-01-17 19:49 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
 2015-01-17 19:49 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
 2015-01-17 19:49 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
 2015-01-17 19:49 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
 2015-01-17 19:49 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
 2015-01-17 19:49 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
 2015-01-17 19:49 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
 2015-01-17 19:49 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
 2015-01-17 19:49 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
 2015-01-10 17:57 - 2015-01-21 14:41 - 00000000 ____D () C:\ProgramData\TBwaccxTj
 2015-01-10 17:57 - 2015-01-10 17:57 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
 2015-01-10 17:56 - 2015-01-10 17:57 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade
 2015-01-10 15:24 - 2015-01-10 15:24 - 00002051 _____ () C:\Users\Public\Desktop\Heroes of Might and Magic IV Winds of War.lnk
 2015-01-10 14:58 - 2015-01-10 15:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3DO
 2015-01-10 14:52 - 2015-01-10 14:52 - 00000000 ____D () C:\Program Files (x86)\3DO
 2015-01-10 14:51 - 1998-10-21 18:43 - 00328704 _____ (InstallShield Software Corporation ) C:\WINDOWS\IsUn0407.exe
 2015-01-09 21:45 - 2015-01-09 21:45 - 13622567 _____ () C:\Users\Carolin\Downloads\heroes4v11to13ge.exe
 2015-01-09 21:45 - 2015-01-09 21:45 - 09200262 _____ () C:\Users\Carolin\Downloads\heroes4v13to20ge.exe
 2015-01-09 21:45 - 2015-01-09 21:45 - 02276924 _____ () C:\Users\Carolin\Downloads\heroes4v20to22ge.exe
 2015-01-09 21:44 - 2015-01-09 21:44 - 07489714 _____ () C:\Users\Carolin\Downloads\h4x1_22to30ger.exe
 2015-01-08 21:20 - 2015-01-08 21:20 - 07306441 _____ () C:\Users\Carolin\Downloads\h4_22to30ger.exe
 2015-01-08 17:22 - 2015-01-08 17:22 - 00000248 _____ () C:\Users\Carolin\Desktop\yugioh.txt
 2014-12-26 13:18 - 2014-12-26 13:19 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
 2014-12-26 13:18 - 2014-12-26 13:19 - 00000776 _____ () C:\WINDOWS\LkmdfCoInst.log
 2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Logitech
 2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\ProgramData\LogiShrd
 2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\ProgramData\Apple
 2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\Program Files\Bonjour
 2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\Program Files (x86)\Bonjour
 2014-12-25 00:14 - 2014-12-25 00:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
 2014-12-25 00:13 - 2014-12-25 00:15 - 00000000 ____D () C:\Program Files\Logitech Gaming Software
 2014-12-25 00:09 - 2014-12-25 00:09 - 67350808 _____ (Logitech Inc.) C:\Users\Carolin\Downloads\LGS_8.57.145_x64_Logitech.exe
 2014-12-25 00:09 - 2014-12-25 00:09 - 63059552 _____ (Logitech Inc.) C:\Users\Carolin\Downloads\LGS_8.57.145_x86_Logitech.exe
 2014-12-25 00:09 - 2014-12-25 00:09 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Logitech
 2014-12-25 00:09 - 2014-12-25 00:09 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Logishrd
 
 ==================== One Month Modified Files and Folders =======
 
 (If an entry is included in the fixlist, the file\folder will be moved.)
 
 2021-10-21 21:36 - 2013-11-06 03:51 - 00000852 ____N () C:\WINDOWS\system32\Drivers\RTKHDRC.dat
 2021-10-04 15:34 - 2013-11-06 03:51 - 00000712 ____N () C:\WINDOWS\system32\Drivers\RTMICEQ0.dat
 2015-01-21 15:03 - 2014-08-23 21:36 - 00000000 ___DO () C:\Users\Carolin\OneDrive
 2015-01-21 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
 2015-01-21 14:58 - 2014-08-23 20:13 - 01672750 _____ () C:\WINDOWS\WindowsUpdate.log
 2015-01-21 14:56 - 2014-03-18 02:50 - 00082938 _____ () C:\WINDOWS\PFRO.log
 2015-01-21 14:56 - 2013-08-22 15:46 - 00301918 _____ () C:\WINDOWS\setupact.log
 2015-01-21 14:56 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
 2015-01-21 14:56 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
 2015-01-21 14:48 - 2014-08-23 12:40 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Pokki
 2015-01-21 14:40 - 2014-09-22 22:09 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
 2015-01-21 14:33 - 2014-08-23 12:49 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-599079236-3312268694-3269153300-1001
 2015-01-21 14:08 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
 2015-01-21 14:06 - 2014-09-03 12:04 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Adobe
 2015-01-21 14:05 - 2014-08-30 16:21 - 00003926 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6116D788-DCF9-4C86-8AEE-4953A6E45227}
 2015-01-21 14:00 - 2014-08-23 18:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
 2015-01-20 21:33 - 2014-10-08 17:13 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Skype
 2015-01-20 21:27 - 2014-08-23 19:56 - 00000000 ____D () C:\Users\Carolin
 2015-01-20 20:14 - 2014-03-18 11:03 - 01806182 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
 2015-01-20 20:14 - 2014-03-18 10:25 - 00781198 _____ () C:\WINDOWS\system32\perfh007.dat
 2015-01-20 20:14 - 2014-03-18 10:25 - 00163922 _____ () C:\WINDOWS\system32\perfc007.dat
 2015-01-20 20:00 - 2014-10-08 17:13 - 00000000 ____D () C:\ProgramData\Skype
 2015-01-20 19:59 - 2014-10-08 17:13 - 00000000 ___RD () C:\Program Files (x86)\Skype
 2015-01-20 08:11 - 2014-11-26 12:41 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
 2015-01-19 12:16 - 2014-09-03 11:16 - 00000370 _____ () C:\WINDOWS\Tasks\SlimCleaner Plus (Scheduled Scan - Carolin).job
 2015-01-19 10:52 - 2014-08-23 16:19 - 00000000 ____D () C:\WINDOWS\system32\MRT
 2015-01-19 10:52 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
 2015-01-19 10:48 - 2014-08-23 16:19 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
 2015-01-19 10:35 - 2014-08-23 18:34 - 00000000 ____D () C:\ProgramData\Cisco
 2015-01-19 10:35 - 2014-08-23 18:34 - 00000000 ____D () C:\Program Files (x86)\Cisco
 2015-01-19 07:54 - 2013-10-09 13:42 - 00000000 ____D () C:\Program Files (x86)\McAfee
 2015-01-17 20:40 - 2014-09-22 22:09 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
 2015-01-10 18:02 - 2014-09-03 11:13 - 00000000 ____D () C:\Users\Carolin\AppData\Local\CrashDumps
 2015-01-10 15:27 - 2014-08-23 12:41 - 00000000 ____D () C:\Users\Carolin\AppData\Local\VirtualStore
 2015-01-08 17:55 - 2014-08-23 17:46 - 00002296 _____ () C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
 2015-01-06 01:08 - 2013-08-22 16:38 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
 2015-01-06 01:08 - 2013-08-22 16:38 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
 2014-12-25 00:13 - 2014-08-23 21:36 - 00000000 ____D () C:\ProgramData\Package Cache
 
 Some content of TEMP:
 ====================
 C:\Users\Carolin\AppData\Local\Temp\3bveq5ob.dll
 C:\Users\Carolin\AppData\Local\Temp\AcerCloudDocsSetup.exe
 C:\Users\Carolin\AppData\Local\Temp\comver.dll
 C:\Users\Carolin\AppData\Local\Temp\gtapi.dll
 C:\Users\Carolin\AppData\Local\Temp\o12swlv3.dll
 C:\Users\Carolin\AppData\Local\Temp\oct3171.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\oct682C.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\oct6903.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\oct86DF.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\oct9BF7.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\octD945.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\octF2EB.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\octFA38.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\ose00000.exe
 C:\Users\Carolin\AppData\Local\Temp\ose00001.exe
 C:\Users\Carolin\AppData\Local\Temp\ose00003.exe
 C:\Users\Carolin\AppData\Local\Temp\Quarantine.exe
 C:\Users\Carolin\AppData\Local\Temp\readSTILog.dll
 C:\Users\Carolin\AppData\Local\Temp\scpD43B.tmp.exe
 C:\Users\Carolin\AppData\Local\Temp\SlimCleanerPlus.x64.exe
 C:\Users\Carolin\AppData\Local\Temp\sqlite3.dll
 
 
 ==================== Bamital & volsnap Check =================
 
 (There is no automatic fix for files that do not pass verification.)
 
 C:\Windows\System32\winlogon.exe => File is digitally signed
 C:\Windows\System32\wininit.exe => File is digitally signed
 C:\Windows\explorer.exe => File is digitally signed
 C:\Windows\SysWOW64\explorer.exe => File is digitally signed
 C:\Windows\System32\svchost.exe => File is digitally signed
 C:\Windows\SysWOW64\svchost.exe => File is digitally signed
 C:\Windows\System32\services.exe => File is digitally signed
 C:\Windows\System32\User32.dll => File is digitally signed
 C:\Windows\SysWOW64\User32.dll => File is digitally signed
 C:\Windows\System32\userinit.exe => File is digitally signed
 C:\Windows\SysWOW64\userinit.exe => File is digitally signed
 C:\Windows\System32\rpcss.dll => File is digitally signed
 C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
 
 
 LastRegBack: 2015-01-19 10:46
 
 ==================== End Of Log ============================
 --- --- ---  
--- --- ---   
Alles richtig gemacht?  
Gruß Carolin |