mami0106 | 21.01.2015 15:12 | Okay, alles gemacht. Hier die Logs:
mbam Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 21.01.2015
Suchlauf-Zeit: 14:11:52
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.21.06
Rootkit Datenbank: v2015.01.14.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Carolin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 389511
Verstrichene Zeit: 21 Min, 8 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 1
PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\aPtfNhADkd.exe, 2828, Löschen bei Neustart, [9971b347b6d3e254fcb6e5c6ad54d927]
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 10
PUP.Optional.SafeWeb.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\aPtfNhADkd, In Quarantäne, [9971b347b6d3e254fcb6e5c6ad54d927],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [a86227d32069af87e5e4fcf8ed1551af],
PUP.Optional.WebSteroids.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, In Quarantäne, [a86227d32069af87e5e4fcf8ed1551af],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [4bbf19e12c5d39fd079143b18d7524dc],
PUP.Optional.DynConIE.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E5A7A645-8318-4895-B85C-EDC606B80DB6}, In Quarantäne, [4bbf19e12c5d39fd079143b18d7524dc],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-599079236-3312268694-3269153300-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, In Quarantäne, [35d523d7b8d177bf8f2005ea11f13ec2],
PUP.Optional.SafeWeb.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SafeWeb, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
PUP.Optional.SearchProtect, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\APPCOMPATFLAGS\INSTALLEDSDB\{cf2797aa-b7ec-e311-8ed9-005056c00008}, In Quarantäne, [cc3ec337ddac2313a8f06194e123e51b],
PUP.Optional.Softonic.A, HKU\S-1-5-21-599079236-3312268694-3269153300-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Softonic, In Quarantäne, [000a35c58cfdaf87798dec8fa3602ad6],
PUP.Optional.MultiIE.A, HKU\S-1-5-21-599079236-3312268694-3269153300-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\DynConIE, In Quarantäne, [d139e8126e1b0531dd00f7f712f2857b],
Registrierungswerte: 1
PUP.Optional.SafeWeb, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\SAFEWEB|HelpLink, hxxp://www.safewebonline.com/about.html, In Quarantäne, [2cdeab4f0c7d4aec52a78f0449bac13f]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 23
PUP.Optional.SafeWeb.A, C:\Users\Carolin\AppData\Local\SafeWeb, In Quarantäne, [e723f9010d7c63d38b202f6c07fc7789],
PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\bin, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\bin, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\SearchProtect\rep, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\bin, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\rep, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.OpenCandy, C:\Users\Carolin\AppData\Roaming\OpenCandy, In Quarantäne, [fa10d92198f1092dde129aa22ed518e8],
PUP.Optional.OpenCandy, C:\Users\Carolin\AppData\Roaming\OpenCandy\1E9F9EE191CA4DF7B10B9C39B1EDAC99, In Quarantäne, [fa10d92198f1092dde129aa22ed518e8],
PUP.Optional.SearchProtect.A, C:\Users\Carolin\AppData\Local\SearchProtect, In Quarantäne, [44c615e54346290d421590c216edf010],
Dateien: 89
PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\aPtfNhADkd.exe, Löschen bei Neustart, [9971b347b6d3e254fcb6e5c6ad54d927],
PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\dat\cbwvsh.exe, Löschen bei Neustart, [58b2a1590d7c0c2a189a7e2dfc055da3],
PUP.Optional.SafeWeb.A, C:\ProgramData\TBwaccxTj\dat\PxEXsGQptN.exe, Löschen bei Neustart, [f6147288bccd3ff7aa085a5126dbcc34],
PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Roaming\OpenCandy\1E9F9EE191CA4DF7B10B9C39B1EDAC99\sp-downloader.exe, In Quarantäne, [b15977836a1f290d16e377c8a06155ab],
PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nst23AF.exe, In Quarantäne, [5caeb5459beea195dd3d6e382fd2c33d],
PUP.Optional.SafeWeb.A, C:\Users\Carolin\AppData\Local\Temp\Setup-2-.exe, In Quarantäne, [a86274863f4aca6c4a3d9fc546ba6b95],
PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nsb28B2.exe, In Quarantäne, [13f719e15e2b87af74a6adf9758cd52b],
PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nsdD54D.exe, In Quarantäne, [38d2ae4c147595a176a4b6f042bf03fd],
PUP.Optional.Conduit.A, C:\Users\Carolin\AppData\Local\Temp\nseD945.exe, In Quarantäne, [f713d3274940a98deb2ffbab08f9ec14],
PUP.Optional.SearchProtect.A, C:\Users\Carolin\AppData\Local\Temp\nsvA94A.tmp, In Quarantäne, [3dcde911a9e0e551b0885d53e819ac54],
PUP.Optional.Softonic, C:\Users\Carolin\Downloads\SoftonicDownloader_fuer_gamespy-arcade.exe, In Quarantäne, [42c8a258b5d474c2931d0c4e49b7748c],
PUP.Optional.OpenCandy, C:\Users\Carolin\Downloads\DTLite4491-0356.exe, In Quarantäne, [b9518c6e9beec86e57e014b1af569967],
PUP.Optional.SearchProtect, C:\Windows\apppatch\apppatch64\VCLdr64.dll, In Quarantäne, [c54503f7c3c64bebdaa484900df58080],
PUP.Optional.SafeWeb.A, C:\Users\Carolin\AppData\Local\SafeWeb\data2.dat, In Quarantäne, [e723f9010d7c63d38b202f6c07fc7789],
PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\app.dat, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\data.dat, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\SafeWeb.ico, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
PUP.Optional.SafeWeb.A, C:\ProgramData\SafeWeb\Uninstall.exe, In Quarantäne, [6e9ccb2f2f5abe78d1dbefacfd06f907],
PUP.Optional.Trovi.A, C:\Users\Carolin\AppData\Roaming\Mozilla\Firefox\Profiles\s8591zzg.default\searchplugins\trovi-search.xml, In Quarantäne, [6d9ded0dea9f6fc7409a5c47d52e0af6],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\EULA.txt, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\Main\rep\SystemRepository.dat, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\style.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\consent.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Consent\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgUninstall.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def-grey.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-default.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-onclick.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Apply-Rollover.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-dia.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-uninstall.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg-with-logo.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bg.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgNotif.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettings.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\bgSettingsDS.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnBlue.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnClose.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\btnSilver.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\button-bg.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_checked.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\checkbox_def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\close-win-over-click.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\gray-bg.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez-selected.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\hez.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\icon-win.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Icon.ico, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\info-icon.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-rollover.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\menu-selected.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-def.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button-selected.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\radio-button2.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\Settings-icon.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\SP_DialogBG.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\text-field.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\v.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\Images\x.png, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\DialogAPI.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\dialogUtils.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\jquery.1.7.1.min.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\json2.min.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\libs\main.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protection\protection.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\protectionDS\protectionDS.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\settings\settings.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\defaults.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.css, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.html, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect.A, C:\Program Files (x86)\SearchProtect\UI\dialogs\uninstall\uninstall.js, In Quarantäne, [08022bcf4f3a043209853aa19f65cd33],
PUP.Optional.SearchProtect, C:\Windows\apppatch\Custom\Custom64\{cf2797aa-b7ec-e311-8ed9-005056c00008}.sdb, In Quarantäne, [1feb23d7f79258de9a02a154e123c13f],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) adwcleaner Code:
# AdwCleaner v4.108 - Bericht erstellt am 21/01/2015 um 14:55:11
# Aktualisiert 17/01/2015 von Xplode
# Database : 2015-01-18.1 [Live]
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Carolin - JOSHI
# Gestartet von : C:\Users\Carolin\Downloads\AdwCleaner_4.108.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Browser
Datei Gelöscht : C:\Users\Carolin\Desktop\Continue Live Installation.lnk
***** [ Tasks ] *****
Task Gelöscht : DriverEasy Scheduled Scan
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\Pokki
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
Daten Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v35.0 (x86 de)
*************************
AdwCleaner[R0].txt - [2247 octets] - [21/01/2015 14:53:04]
AdwCleaner[S0].txt - [1748 octets] - [21/01/2015 14:55:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1808 octets] ########## jrt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 8.1 x64
Ran by Carolin on 21.01.2015 at 15:01:46,11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
Successfully deleted: [Registry Key - Orphan] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
Successfully deleted: [Registry Key - Orphan] HKEY_CLASSES_ROOT\CLSID\{0E8A89AD-95D7-40EB-8D9D-083EF7066A01}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Carolin\AppData\Roaming\mozilla\firefox\profiles\s8591zzg.default\minidumps [5 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21.01.2015 at 15:04:55,61
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ frst:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2015
Ran by Carolin (administrator) on JOSHI on 21-01-2015 15:06:25
Running from C:\Users\Carolin\Downloads
Loaded Profiles: Carolin (Available profiles: Carolin)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimServiceFactory.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe
() C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe
(Akamai Technologies, Inc.) C:\Users\Carolin\AppData\Local\Akamai\netsession_win.exe
(SlimWare Utilities, Inc.) C:\Program Files\SlimCleaner Plus\SlimService.exe
(Akamai Technologies, Inc.) C:\Users\Carolin\AppData\Local\Akamai\netsession_win.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Thisisu) C:\Users\Carolin\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-22] (ELAN Microelectronics Corp.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-03] (Adobe Systems Incorporated)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13427784 2013-03-18] (Realtek Semiconductor)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-08-30] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-09] (AVAST Software)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2014-11-19] (Cisco Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [132736 2013-09-07] ( (Atheros Communications))
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Run: [SlimCleaner Plus] => C:\Program Files\SlimCleaner Plus\SlimCleanerPlus.exe [26163008 2014-08-04] (SlimWare Utilities, Inc.)
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 12 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [1400224 2013-09-25] (Adobe Systems Incorporated)
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Carolin\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\RunOnce: [Application Restart #0] => C:\Users\Carolin\AppData\Local\Pokki\Engine\HostAppService.exe [7843656 2015-01-01] (Pokki)
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\MountPoints2: {49bde67e-2b06-11e4-be78-00059a3c7a00} - "E:\Setup.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (No File)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.com/search?q={searchTerms}
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?trackid=sp-006
HKU\S-1-5-21-599079236-3312268694-3269153300-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.google.com/?trackid=sp-006
SearchScopes: HKLM-x32 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-599079236-3312268694-3269153300-1001 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = https://www.google.com/search?q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Webtestaufzeichnung 10.0-Hilfsprogramm -> {DDA57003-0068-4ed2-9D32-4D1EC707D94D} -> C:\Program Files (x86)\Microsoft Visual Studio 10.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Carolin\AppData\Roaming\Mozilla\Firefox\Profiles\s8591zzg.default
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF Extension: Adblock Plus - C:\Users\Carolin\AppData\Roaming\Mozilla\Firefox\Profiles\s8591zzg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-09-14]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2013-10-09]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-26]
FF HKU\S-1-5-21-599079236-3312268694-3269153300-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-01-17]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-01-17]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-26]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor12.0; C:\Program Files (x86)\Adobe\Elements 12 Organizer\PhotoshopElementsFileAgent.exe [181152 2013-09-25] (Adobe Systems Incorporated)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [312448 2013-09-07] (Windows (R) Win 7 DDK provider)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-26] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-26] (Avast Software)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [663592 2013-07-05] (Acer Incorporated)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [314696 2014-05-20] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-04] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-06-18] (Acer Incorporate)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [154320 2014-12-03] (McAfee, Inc.)
S3 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4230016 2013-01-28] (Symantec Corporation)
R2 PSI_SVC_2_x64; C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 SlimService; C:\Program Files\SlimCleaner Plus\SlimServiceFactory.exe [244544 2014-08-04] (SlimWare Utilities, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2014-07-21] (Advanced Micro Devices, Inc.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-26] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-26] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-26] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-26] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-26] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-26] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-26] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-26] ()
R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-09-07] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0403000.00E\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-08-23] (Disc Soft Ltd)
S3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
S3 LGSUsbFilt; C:\Windows\system32\DRIVERS\LGSUsbFilt.Sys [41752 2013-05-30] (Logitech Inc.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-04] (Intel Corporation)
R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-07-19] (Corel Corporation)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
S3 SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [16152 2014-09-03] ()
U4 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-26] (Avast Software)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52592 2014-06-11] (Cisco Systems, Inc.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-21 15:06 - 2015-01-21 15:06 - 00020133 _____ () C:\Users\Carolin\Downloads\FRST.txt
2015-01-21 15:04 - 2015-01-21 15:04 - 00001475 _____ () C:\Users\Carolin\Desktop\JRT.txt
2015-01-21 15:01 - 2015-01-21 15:01 - 00000000 ____D () C:\WINDOWS\ERUNT
2015-01-21 14:53 - 2015-01-21 14:55 - 00000000 ____D () C:\AdwCleaner
2015-01-21 14:51 - 2015-01-21 14:51 - 00019368 _____ () C:\Users\Carolin\Desktop\mbam.txt
2015-01-21 14:11 - 2015-01-21 14:48 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-01-21 14:11 - 2015-01-21 14:11 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-21 14:11 - 2015-01-21 14:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-21 14:11 - 2015-01-21 14:11 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-21 14:11 - 2015-01-21 14:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-21 14:11 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-01-21 14:11 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-01-21 14:11 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-01-20 22:54 - 2015-01-20 22:54 - 02186752 _____ () C:\Users\Carolin\Downloads\AdwCleaner_4.108.exe
2015-01-20 22:54 - 2015-01-20 22:54 - 01707939 _____ (Thisisu) C:\Users\Carolin\Downloads\JRT.exe
2015-01-20 22:52 - 2015-01-20 22:52 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Carolin\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-20 22:46 - 2015-01-20 22:46 - 02785665 _____ (PortableApps.com) C:\Users\Carolin\Downloads\RevoUninstallerPortable_1.95_Rev_2.paf.exe
2015-01-20 22:46 - 2015-01-20 22:46 - 00000000 ____D () C:\Users\Carolin\Downloads\RevoUninstallerPortable
2015-01-20 22:40 - 2015-01-20 22:40 - 00001284 _____ () C:\Users\Carolin\Desktop\Revo Uninstaller.lnk
2015-01-20 22:40 - 2015-01-20 22:40 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-01-20 22:39 - 2015-01-20 22:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Carolin\Downloads\revosetup95.exe
2015-01-20 21:31 - 2015-01-20 21:31 - 00380416 _____ () C:\Users\Carolin\Downloads\Gmer-19357.exe
2015-01-20 21:28 - 2015-01-21 15:06 - 00000000 ____D () C:\FRST
2015-01-20 21:28 - 2015-01-20 21:28 - 02126848 _____ (Farbar) C:\Users\Carolin\Downloads\FRST64.exe
2015-01-20 21:27 - 2015-01-20 21:27 - 00000168 _____ () C:\Users\Carolin\defogger_reenable
2015-01-20 21:26 - 2015-01-20 21:26 - 00050477 _____ () C:\Users\Carolin\Downloads\Defogger.exe
2015-01-20 14:09 - 2015-01-20 14:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-19 10:35 - 2015-01-19 10:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cisco
2015-01-17 19:49 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-01-17 19:49 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-01-17 19:49 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-01-17 19:49 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-17 19:49 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-01-17 19:49 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-01-17 19:49 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-01-17 19:49 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-01-17 19:49 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-01-17 19:49 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-01-17 19:49 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-01-17 19:49 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-01-17 19:49 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-01-17 19:49 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-01-17 19:49 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-01-17 19:49 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2015-01-17 19:49 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2015-01-17 19:49 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-01-17 19:49 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-01-17 19:49 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-01-17 19:49 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-01-17 19:49 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2015-01-17 19:49 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2015-01-17 19:49 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-01-17 19:49 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-01-17 19:49 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-01-17 19:49 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2015-01-17 19:49 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2015-01-17 19:49 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2015-01-17 19:49 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-01-17 19:49 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2015-01-10 17:57 - 2015-01-21 14:41 - 00000000 ____D () C:\ProgramData\TBwaccxTj
2015-01-10 17:57 - 2015-01-10 17:57 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameSpy Arcade
2015-01-10 17:56 - 2015-01-10 17:57 - 00000000 ____D () C:\Program Files (x86)\GameSpy Arcade
2015-01-10 15:24 - 2015-01-10 15:24 - 00002051 _____ () C:\Users\Public\Desktop\Heroes of Might and Magic IV Winds of War.lnk
2015-01-10 14:58 - 2015-01-10 15:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3DO
2015-01-10 14:52 - 2015-01-10 14:52 - 00000000 ____D () C:\Program Files (x86)\3DO
2015-01-10 14:51 - 1998-10-21 18:43 - 00328704 _____ (InstallShield Software Corporation ) C:\WINDOWS\IsUn0407.exe
2015-01-09 21:45 - 2015-01-09 21:45 - 13622567 _____ () C:\Users\Carolin\Downloads\heroes4v11to13ge.exe
2015-01-09 21:45 - 2015-01-09 21:45 - 09200262 _____ () C:\Users\Carolin\Downloads\heroes4v13to20ge.exe
2015-01-09 21:45 - 2015-01-09 21:45 - 02276924 _____ () C:\Users\Carolin\Downloads\heroes4v20to22ge.exe
2015-01-09 21:44 - 2015-01-09 21:44 - 07489714 _____ () C:\Users\Carolin\Downloads\h4x1_22to30ger.exe
2015-01-08 21:20 - 2015-01-08 21:20 - 07306441 _____ () C:\Users\Carolin\Downloads\h4_22to30ger.exe
2015-01-08 17:22 - 2015-01-08 17:22 - 00000248 _____ () C:\Users\Carolin\Desktop\yugioh.txt
2014-12-26 13:18 - 2014-12-26 13:19 - 00018960 _____ (Logitech, Inc.) C:\WINDOWS\system32\Drivers\LNonPnP.sys
2014-12-26 13:18 - 2014-12-26 13:19 - 00000776 _____ () C:\WINDOWS\LkmdfCoInst.log
2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Logitech
2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\ProgramData\LogiShrd
2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\ProgramData\Apple
2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\Program Files\Bonjour
2014-12-25 00:15 - 2014-12-25 00:15 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-12-25 00:14 - 2014-12-25 00:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2014-12-25 00:13 - 2014-12-25 00:15 - 00000000 ____D () C:\Program Files\Logitech Gaming Software
2014-12-25 00:09 - 2014-12-25 00:09 - 67350808 _____ (Logitech Inc.) C:\Users\Carolin\Downloads\LGS_8.57.145_x64_Logitech.exe
2014-12-25 00:09 - 2014-12-25 00:09 - 63059552 _____ (Logitech Inc.) C:\Users\Carolin\Downloads\LGS_8.57.145_x86_Logitech.exe
2014-12-25 00:09 - 2014-12-25 00:09 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Logitech
2014-12-25 00:09 - 2014-12-25 00:09 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Logishrd
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2021-10-21 21:36 - 2013-11-06 03:51 - 00000852 ____N () C:\WINDOWS\system32\Drivers\RTKHDRC.dat
2021-10-04 15:34 - 2013-11-06 03:51 - 00000712 ____N () C:\WINDOWS\system32\Drivers\RTMICEQ0.dat
2015-01-21 15:03 - 2014-08-23 21:36 - 00000000 ___DO () C:\Users\Carolin\OneDrive
2015-01-21 15:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-01-21 14:58 - 2014-08-23 20:13 - 01672750 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-21 14:56 - 2014-03-18 02:50 - 00082938 _____ () C:\WINDOWS\PFRO.log
2015-01-21 14:56 - 2013-08-22 15:46 - 00301918 _____ () C:\WINDOWS\setupact.log
2015-01-21 14:56 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-21 14:56 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-01-21 14:48 - 2014-08-23 12:40 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Pokki
2015-01-21 14:40 - 2014-09-22 22:09 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-01-21 14:33 - 2014-08-23 12:49 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-599079236-3312268694-3269153300-1001
2015-01-21 14:08 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-21 14:06 - 2014-09-03 12:04 - 00000000 ____D () C:\Users\Carolin\AppData\Local\Adobe
2015-01-21 14:05 - 2014-08-30 16:21 - 00003926 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6116D788-DCF9-4C86-8AEE-4953A6E45227}
2015-01-21 14:00 - 2014-08-23 18:10 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-20 21:33 - 2014-10-08 17:13 - 00000000 ____D () C:\Users\Carolin\AppData\Roaming\Skype
2015-01-20 21:27 - 2014-08-23 19:56 - 00000000 ____D () C:\Users\Carolin
2015-01-20 20:14 - 2014-03-18 11:03 - 01806182 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-01-20 20:14 - 2014-03-18 10:25 - 00781198 _____ () C:\WINDOWS\system32\perfh007.dat
2015-01-20 20:14 - 2014-03-18 10:25 - 00163922 _____ () C:\WINDOWS\system32\perfc007.dat
2015-01-20 20:00 - 2014-10-08 17:13 - 00000000 ____D () C:\ProgramData\Skype
2015-01-20 19:59 - 2014-10-08 17:13 - 00000000 ___RD () C:\Program Files (x86)\Skype
2015-01-20 08:11 - 2014-11-26 12:41 - 00004182 _____ () C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-01-19 12:16 - 2014-09-03 11:16 - 00000370 _____ () C:\WINDOWS\Tasks\SlimCleaner Plus (Scheduled Scan - Carolin).job
2015-01-19 10:52 - 2014-08-23 16:19 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-01-19 10:52 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-19 10:48 - 2014-08-23 16:19 - 113365784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-01-19 10:35 - 2014-08-23 18:34 - 00000000 ____D () C:\ProgramData\Cisco
2015-01-19 10:35 - 2014-08-23 18:34 - 00000000 ____D () C:\Program Files (x86)\Cisco
2015-01-19 07:54 - 2013-10-09 13:42 - 00000000 ____D () C:\Program Files (x86)\McAfee
2015-01-17 20:40 - 2014-09-22 22:09 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-01-10 18:02 - 2014-09-03 11:13 - 00000000 ____D () C:\Users\Carolin\AppData\Local\CrashDumps
2015-01-10 15:27 - 2014-08-23 12:41 - 00000000 ____D () C:\Users\Carolin\AppData\Local\VirtualStore
2015-01-08 17:55 - 2014-08-23 17:46 - 00002296 _____ () C:\Users\Carolin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-01-06 01:08 - 2013-08-22 16:38 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-01-06 01:08 - 2013-08-22 16:38 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-25 00:13 - 2014-08-23 21:36 - 00000000 ____D () C:\ProgramData\Package Cache
Some content of TEMP:
====================
C:\Users\Carolin\AppData\Local\Temp\3bveq5ob.dll
C:\Users\Carolin\AppData\Local\Temp\AcerCloudDocsSetup.exe
C:\Users\Carolin\AppData\Local\Temp\comver.dll
C:\Users\Carolin\AppData\Local\Temp\gtapi.dll
C:\Users\Carolin\AppData\Local\Temp\o12swlv3.dll
C:\Users\Carolin\AppData\Local\Temp\oct3171.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\oct682C.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\oct6903.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\oct86DF.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\oct9BF7.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\octD945.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\octF2EB.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\octFA38.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\ose00000.exe
C:\Users\Carolin\AppData\Local\Temp\ose00001.exe
C:\Users\Carolin\AppData\Local\Temp\ose00003.exe
C:\Users\Carolin\AppData\Local\Temp\Quarantine.exe
C:\Users\Carolin\AppData\Local\Temp\readSTILog.dll
C:\Users\Carolin\AppData\Local\Temp\scpD43B.tmp.exe
C:\Users\Carolin\AppData\Local\Temp\SlimCleanerPlus.x64.exe
C:\Users\Carolin\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-19 10:46
==================== End Of Log ============================ --- --- ---
--- --- ---
Alles richtig gemacht?
Gruß Carolin |