Junkware Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.7 (09.01.2013:1)
OS: Windows 8 Pro x64
Ran by LilLady on 03.09.2013 at 13:49:05,87
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 03.09.2013 at 13:53:49,18
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ bei AdWCleaner tut sich gar nichts *ratlos*
ABER ich hatte den ADWCleaner am 30.8. mal gestartet und dabei entstand dieses File: Code:
# AdwCleaner v3.001 - Report created 30/08/2013 at 14:01:22
# Updated 24/08/2013 by Xplode
# Operating System : Windows 8 Pro (64 bits)
# Username : LilLady - LILLADY-PC
# Running from : C:\Users\LilLady\Downloads\adwcleaner.exe
# Option : Clean
***** [ Services ] *****
***** [ Files / Folders ] *****
Folder Deleted : C:\ProgramData\apn
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\Browser Manager
Folder Deleted : C:\ProgramData\search protection
Folder Deleted : C:\ProgramData\Tarma Installer
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\optimizer pro
Folder Deleted : C:\Users\LilLady\AppData\Local\PutLockerDownloader
Folder Deleted : C:\Users\LilLady\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\LilLady\AppData\Roaming\Babylon
Folder Deleted : C:\Users\LilLady\AppData\Roaming\Common\LuaRT
Folder Deleted : C:\Users\LilLady\AppData\Roaming\DataMgr
Folder Deleted : C:\Users\LilLady\AppData\Roaming\dvdvideosoftiehelpers
Folder Deleted : C:\Users\LilLady\AppData\Roaming\Intermediate
Folder Deleted : C:\Users\LilLady\AppData\Roaming\OpenCandy
Folder Deleted : C:\Users\LilLady\AppData\Roaming\optimizer pro
Folder Deleted : C:\Users\LilLady\AppData\Roaming\SCheck
Folder Deleted : C:\Users\LilLady\AppData\Roaming\SSync
Folder Deleted : C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Movie2KDownloader.com
Folder Deleted : C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\d9zc4d6x.default\jetpack
File Deleted : C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\d9zc4d6x.default\Extensions\om@offermosquito.com.xpi
[x] Not Deleted : C:\Users\LilLady\AppData\Local\Temp\Searchqu.ini
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\adawaretb.xml
File Deleted : C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\d9zc4d6x.default\searchplugins\Babylon.xml
File Deleted : C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\d9zc4d6x.default\searchplugins\delta.xml
File Deleted : C:\Program Files (x86)\Mozilla Firefox\searchplugins\Search_Results.xml
File Deleted : C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\d9zc4d6x.default\\invalidprefs.js
File Deleted : C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\d9zc4d6x.default\user.js
***** [ Shortcuts ] *****
***** [ Registry ] *****
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\blaofbhgbmeikidhlkmjhbkbfohpgekf
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [DataMgr]
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Intermediate]
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [scheck]
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [ssync]
[x] Not Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
[x] Not Deleted : HKLM\SOFTWARE\Classes\driverscanner
Key Deleted : HKLM\SOFTWARE\Classes\Movie2KDownloader
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
[x] Not Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
[x] Not Deleted : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}
[x] Not Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
[x] Not Deleted : HKLM\SOFTWARE\Classes\CLSID\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
[x] Not Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
[x] Not Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401}
[x] Not Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5}
[x] Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
[x] Not Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3EC1A45C-8BC3-4BFE-B226-4051C5D3D068}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
[x] Not Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6}
[x] Not Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}
Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2413}
Key Deleted : HKCU\Software\1ClickDownload
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\BI
Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\delta LTD
Key Deleted : HKCU\Software\httogroup
Key Deleted : HKCU\Software\OCS
Key Deleted : HKCU\Software\Optimizer Pro
Key Deleted : HKCU\Software\piccshare
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\Software\BabylonToolbar
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\Software\SearchquSRTB
Key Deleted : HKLM\Software\Uniblue\DriverScanner
[x] Not Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : [x64] HKLM\SOFTWARE\DataMngr
Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16660
Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
-\\ Mozilla Firefox v23.0.1 (de)
[ File : C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\d9zc4d6x.default\prefs.js ]
Line Deleted : user_pref("browser.newtabpage.pinned", "[{\"url\":\"hxxps://mail.google.com/mail/?shva=1#inbox\",\"title\":\"Posteingang - janine.salzwedel@googlemail.com - Gmail\"},{\"url\":\"hxxps://www.facebook.co[...]
Line Deleted : user_pref("extensions.delta.admin", false);
Line Deleted : user_pref("extensions.delta.aflt", "babsst");
Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}");
Line Deleted : user_pref("extensions.delta.autoRvrt", "false");
Line Deleted : user_pref("extensions.delta.bbDpng", "18");
Line Deleted : user_pref("extensions.delta.cntry", "DE");
Line Deleted : user_pref("extensions.delta.dfltLng", "de");
Line Deleted : user_pref("extensions.delta.excTlbr", false);
Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true);
Line Deleted : user_pref("extensions.delta.hdrMd5", "87D23D50BAD3513692D5F2CE56AC71B5");
Line Deleted : user_pref("extensions.delta.id", "9c1eecad00000000000000224311078e");
Line Deleted : user_pref("extensions.delta.instlDay", "15904");
Line Deleted : user_pref("extensions.delta.instlRef", "sst");
Line Deleted : user_pref("extensions.delta.lastVrsnTs", "1.8.21.522:35:41");
Line Deleted : user_pref("extensions.delta.newTab", false);
Line Deleted : user_pref("extensions.delta.prdct", "delta");
Line Deleted : user_pref("extensions.delta.prtnrId", "delta");
Line Deleted : user_pref("extensions.delta.rvrt", "false");
Line Deleted : user_pref("extensions.delta.sg", "azb");
Line Deleted : user_pref("extensions.delta.smplGrp", "none");
Line Deleted : user_pref("extensions.delta.tlbrId", "base");
Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", "");
Line Deleted : user_pref("extensions.delta.vrsn", "1.8.21.5");
Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.21.522:35:41");
Line Deleted : user_pref("extensions.delta.vrsni", "1.8.21.5");
Line Deleted : user_pref("extensions.delta_i.babExt", "");
Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=119821&tsp=4947");
Line Deleted : user_pref("extensions.delta_i.srcExt", "ss");
Line Deleted : user_pref("extensions.enabledAddons", "DivXWebPlayer%40divx.com:2.0.2.039,%7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130515,om%40offermosquito.com:0.6.2,%7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:23[...]
Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"web2pdfextension@web2pdf.adobedotcom\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Adobe\\\\Acrobat 10.0\\\\Acro[...]
Line Deleted : user_pref("om.config", "{\"active\":true,\"name\":\"twde\",\"id\":25,\"dispId\":\"CH-25\",\"aboutLink\":\"\",\"trackingGeneral\":true,\"gaAccount\":\"UA-39484183-1\",\"gaDomain\":\"offermosquito.com\"[...]
*************************
AdwCleaner[R0].txt - [10644 octets] - [30/08/2013 13:56:06]
AdwCleaner[S0].txt - [9885 octets] - [30/08/2013 14:01:22]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [9945 octets] ########## Frisches FRST Log:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2013 01
Ran by LilLady (administrator) on LILLADY-PC on 03-09-2013 13:57:38
Running from C:\Users\LilLady\Downloads
Windows 8 Pro (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Policies\Explorer: [NoDrives] 0
HKCU\...\Policies\Explorer: [NoDrives] 0
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\LilLady\AppData\Roaming\Mozilla\Firefox\Profiles\xek8zhhi.default
FF Homepage: www.google.de
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
==================== Services (Whitelisted) =================
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [15440 2012-07-26] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 XUIF; C:\Windows\System32\Drivers\x10ufx2.sys [33048 2006-11-30] (X10 Wireless Technology, Inc.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-03 13:49 - 2013-09-03 13:49 - 00000000 ____D C:\WINDOWS\ERUNT
2013-09-03 13:48 - 2013-09-03 13:48 - 01028757 _____ (Thisisu) C:\Users\LilLady\Downloads\JRT.exe
2013-09-03 13:35 - 2013-09-03 13:35 - 01037134 _____ C:\Users\LilLady\Downloads\adwcleaner(1).exe
2013-09-03 13:33 - 2013-09-03 13:33 - 00000117 _____ C:\WINDOWS\system32\netcfg-37580.txt
2013-09-03 13:32 - 2013-09-03 13:32 - 00000117 _____ C:\WINDOWS\system32\netcfg-4151171.txt
2013-09-03 13:24 - 2013-09-03 13:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\LilLady\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-03 13:24 - 2013-09-03 13:24 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-03 13:24 - 2013-09-03 13:24 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Malwarebytes
2013-09-03 13:24 - 2013-09-03 13:24 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-03 13:24 - 2013-09-03 13:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-03 13:24 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-09-03 13:20 - 2013-09-03 13:20 - 00004887 ____C C:\ComboFix.txt
2013-09-03 13:12 - 2011-06-26 08:45 - 00256000 _____ C:\WINDOWS\PEV.exe
2013-09-03 13:12 - 2010-11-07 19:20 - 00208896 _____ C:\WINDOWS\MBR.exe
2013-09-03 13:12 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\WINDOWS\NIRCMD.exe
2013-09-03 13:12 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\WINDOWS\SWREG.exe
2013-09-03 13:12 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\WINDOWS\SWSC.exe
2013-09-03 13:12 - 2000-08-31 02:00 - 00212480 _____ (SteelWerX) C:\WINDOWS\SWXCACLS.exe
2013-09-03 13:12 - 2000-08-31 02:00 - 00098816 _____ C:\WINDOWS\sed.exe
2013-09-03 13:12 - 2000-08-31 02:00 - 00080412 _____ C:\WINDOWS\grep.exe
2013-09-03 13:12 - 2000-08-31 02:00 - 00068096 _____ C:\WINDOWS\zip.exe
2013-09-03 13:11 - 2013-09-03 13:17 - 00000000 ____D C:\WINDOWS\erdnt
2013-09-03 13:11 - 2013-09-03 13:11 - 05119472 ____R (Swearware) C:\Users\LilLady\Downloads\ComboFix.exe
2013-09-03 13:11 - 2013-09-03 13:11 - 00000117 _____ C:\WINDOWS\system32\netcfg-2846690.txt
2013-09-03 13:11 - 2013-09-03 13:11 - 00000117 _____ C:\WINDOWS\system32\netcfg-2846628.txt
2013-09-03 12:29 - 2013-09-03 12:29 - 00019402 _____ C:\Users\LilLady\Desktop\Addition.txt
2013-09-03 12:28 - 2013-09-03 12:28 - 00033116 _____ C:\Users\LilLady\Desktop\FRST.txt
2013-09-03 12:28 - 2013-09-03 12:28 - 00019402 _____ C:\Users\LilLady\Downloads\Addition.txt
2013-09-03 12:26 - 2013-09-03 12:26 - 00000000 ___DC C:\FRST
2013-09-03 12:25 - 2013-09-03 12:26 - 01950474 _____ (Farbar) C:\Users\LilLady\Downloads\FRST64.exe
2013-09-03 12:25 - 2013-09-03 12:25 - 00002067 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2013-09-03 12:24 - 2013-09-03 12:24 - 00000117 _____ C:\WINDOWS\system32\netcfg-52057.txt
2013-09-03 12:23 - 2013-09-03 12:23 - 00000117 _____ C:\WINDOWS\system32\netcfg-3890883.txt
2013-09-03 11:59 - 2013-09-03 12:45 - 00000000 ___DC C:\Windows.old
2013-09-03 11:59 - 2013-09-03 11:59 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-09-03 11:51 - 2013-09-03 11:51 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-09-03 11:50 - 2013-09-03 13:33 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-03 11:50 - 2013-09-03 11:51 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-09-03 11:50 - 2013-09-03 11:06 - 00000000 ____D C:\WINDOWS\Panther
2013-09-03 11:50 - 2013-01-18 17:00 - 06390048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2013-09-03 11:50 - 2013-01-18 17:00 - 03460896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2013-09-03 11:50 - 2013-01-18 17:00 - 02558240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2013-09-03 11:50 - 2013-01-18 17:00 - 00884512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2013-09-03 11:50 - 2013-01-18 17:00 - 00118560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2013-09-03 11:50 - 2013-01-18 17:00 - 00063776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2013-09-03 11:49 - 2013-09-03 12:42 - 00000000 ___DC C:\$SysReset
2013-09-03 11:49 - 2013-09-03 11:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-09-03 11:49 - 2013-02-26 00:32 - 00061216 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2013-09-03 11:49 - 2013-02-26 00:32 - 00053024 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2013-09-03 11:48 - 2013-09-03 11:51 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-09-03 11:46 - 2013-09-03 11:46 - 00003198 _____ C:\WINDOWS\System32\Tasks\{B18349A5-C633-4651-8AAA-2F98942E946D}
2013-09-03 11:39 - 2013-09-03 13:33 - 00000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
2013-09-03 11:39 - 2013-09-03 11:42 - 00004869 _____ C:\WINDOWS\system32\lvcoinst.log
2013-09-03 11:39 - 2013-09-03 11:40 - 00000000 ___SD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0
2013-09-03 11:39 - 2013-09-03 11:39 - 00001188 _____ C:\Users\LilLady\Desktop\OpenOffice 4.0.0.lnk
2013-09-03 11:39 - 2013-09-03 11:39 - 00000000 ____D C:\Program Files\Common Files\logishrd
2013-09-03 11:38 - 2013-09-03 11:39 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-03 11:36 - 2013-09-03 11:36 - 00000000 ____D C:\ProgramData\Adobe
2013-09-03 11:34 - 2013-09-03 11:45 - 00000000 ____D C:\Users\LilLady\AppData\Local\Adobe
2013-09-03 11:31 - 2013-09-03 11:31 - 00000000 ____D C:\Users\LilLady\Desktop\OpenOffice 4.0.0 (de) Installation Files
2013-09-03 11:24 - 2013-09-03 11:24 - 00000117 _____ C:\WINDOWS\system32\netcfg-365011.txt
2013-09-03 11:24 - 2013-09-03 11:24 - 00000117 _____ C:\WINDOWS\system32\netcfg-363123.txt
2013-09-03 11:23 - 2013-09-03 11:24 - 00001203 _____ C:\WINDOWS\system32\netcfg-347570.txt
2013-09-03 11:23 - 2013-09-03 11:24 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Mozilla
2013-09-03 11:23 - 2013-09-03 11:23 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\Users\LilLady\AppData\Local\Mozilla
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-03 11:21 - 2013-09-03 11:35 - 450907216 _____ (G Data Software AG) C:\Users\LilLady\Downloads\GER_R_FUL_2013_IS.exe
2013-09-03 11:20 - 2013-09-03 11:20 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Macromedia
2013-09-03 11:19 - 2013-09-03 11:19 - 00000117 _____ C:\WINDOWS\system32\netcfg-51729.txt
2013-09-03 11:17 - 2013-09-03 11:17 - 00000117 _____ C:\WINDOWS\system32\netcfg-819036.txt
2013-09-03 11:14 - 2013-09-03 12:42 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-261323904-3986566715-3217930549-1001
2013-09-03 11:09 - 2013-09-03 11:09 - 00024574 _____ C:\Users\LilLady\Desktop\Entfernte Anwendungen.html
2013-09-03 11:08 - 2013-09-03 11:08 - 00001444 _____ C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-03 11:08 - 2013-09-03 11:08 - 00000000 ___RD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-03 11:08 - 2013-09-03 11:08 - 00000000 ___RD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-03 11:08 - 2013-09-03 11:08 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Adobe
2013-09-03 11:07 - 2013-09-03 11:07 - 00000020 ___SH C:\Users\LilLady\ntuser.ini
2013-09-03 11:07 - 2013-09-03 11:07 - 00000000 ____D C:\Users\LilLady\AppData\Local\VirtualStore
2013-09-03 11:07 - 2013-09-03 11:07 - 00000000 ____D C:\ProgramData\PRICache
2013-09-03 11:06 - 2013-09-03 13:45 - 00453529 _____ C:\WINDOWS\WindowsUpdate.log
2013-09-03 11:06 - 2013-09-03 11:06 - 00000117 _____ C:\WINDOWS\system32\netcfg-128342.txt
2013-09-03 11:06 - 2013-09-03 11:06 - 00000117 _____ C:\WINDOWS\system32\netcfg-128264.txt
2013-09-03 11:06 - 2013-09-03 11:06 - 00000117 _____ C:\WINDOWS\system32\netcfg-128061.txt
2013-09-03 11:06 - 2013-09-03 11:06 - 00000000 ____D C:\WINDOWS\CSC
2013-09-03 11:05 - 2013-09-03 11:08 - 00000000 ____D C:\Users\LilLady
2013-09-03 11:05 - 2013-09-03 11:06 - 00000117 _____ C:\WINDOWS\system32\netcfg-124878.txt
2013-09-03 11:05 - 2013-09-03 11:05 - 00017148 _____ C:\WINDOWS\diagwrn.xml
2013-09-03 11:05 - 2013-09-03 11:05 - 00017148 _____ C:\WINDOWS\diagerr.xml
2013-09-03 11:05 - 2013-09-03 11:05 - 00001139 _____ C:\WINDOWS\system32\netcfg-68765.txt
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Vorlagen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Startmenü
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Netzwerkumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Lokale Einstellungen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Eigene Dateien
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Druckumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Documents\Eigene Musik
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Documents\Eigene Bilder
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\AppData\Local\Verlauf
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\AppData\Local\Anwendungsdaten
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Anwendungsdaten
2013-09-03 11:05 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2013-09-03 11:05 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2013-09-03 11:05 - 2012-07-26 10:13 - 00000000 ___RD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2013-09-03 11:05 - 2012-07-26 10:13 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-09-03 11:02 - 2013-09-03 11:02 - 00001134 _____ C:\WINDOWS\system32\netcfg-97719.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00001099 _____ C:\WINDOWS\system32\netcfg-130869.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000185 _____ C:\WINDOWS\system32\netcfg-108342.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000164 _____ C:\WINDOWS\system32\netcfg-101946.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000161 _____ C:\WINDOWS\system32\netcfg-104520.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-132117.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-104052.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-103069.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-101541.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000159 _____ C:\WINDOWS\system32\netcfg-102648.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000157 _____ C:\WINDOWS\system32\netcfg-103584.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000157 _____ C:\WINDOWS\system32\netcfg-101182.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000150 _____ C:\WINDOWS\system32\netcfg-102274.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-09-03 11:01 - 2013-09-03 11:01 - 00286200 _____ C:\WINDOWS\Minidump\090313-71479-01.dmp
2013-09-03 11:01 - 2013-09-03 11:01 - 00000000 ____D C:\WINDOWS\Minidump
2013-09-03 11:00 - 2013-09-03 13:33 - 00001240 _____ C:\WINDOWS\PFRO.log
2013-09-03 11:00 - 2013-09-03 11:00 - 268649420 _____ C:\WINDOWS\MEMORY.DMP
2013-08-30 14:40 - 2013-08-30 14:43 - 48494759 _____ C:\Users\LilLady\Documents\(5-5)ARD Der große Crash Die Wirtschaftskrise 1929 in Deutschland.flv
2013-08-30 14:21 - 2013-08-30 14:21 - 00804552 _____ (Koyote-Lab Inc.) C:\Users\LilLady\Downloads\FreeFLVConverter75Setup(1).exe
2013-08-30 14:11 - 2013-08-30 14:14 - 64915018 _____ C:\Users\LilLady\Documents\(2-5)ARD Der große Crash Die Wirtschaftskrise 1929 in Deutschland.flv
2013-08-30 14:10 - 2013-08-30 14:13 - 66620799 _____ C:\Users\LilLady\Documents\(1-5)ARD Der große Crash - Die Wirtschaftskrise 1929 in Deutschland.wmv.flv
2013-08-30 13:56 - 2013-09-03 13:44 - 00000000 ___DC C:\AdwCleaner
2013-08-30 13:53 - 2013-08-30 13:53 - 00994642 _____ C:\Users\LilLady\Downloads\adwcleaner.exe
2013-08-29 12:04 - 2013-08-29 12:05 - 05843488 _____ (Mischel Internet Security ) C:\Users\LilLady\Downloads\TrojanHunterSetup_5.5_Build_1003.exe
2013-08-27 11:52 - 2013-08-27 11:52 - 00004608 ___SH C:\Users\LilLady\Documents\Thumbs.db
2013-08-27 11:43 - 2013-08-27 11:43 - 11067384 _____ C:\Users\LilLady\Downloads\YTD43Setup.exe
2013-08-25 22:42 - 2013-08-25 22:42 - 00011229 _____ C:\Users\LilLady\Desktop\Unbenannt 2.odt
2013-08-24 12:14 - 2013-08-24 12:15 - 00000000 ____D C:\Users\Public\Documents\BitRaider
2013-08-24 12:08 - 2013-08-24 12:12 - 00014632 _____ C:\Users\LilLady\Documents\Install STAR WARS The Old Republic.log
2013-08-24 12:06 - 2013-08-24 12:06 - 39777624 _____ C:\Users\LilLady\Downloads\SWTOR_setup.exe
2013-08-20 18:46 - 2013-08-20 18:46 - 01681573 _____ C:\Users\LilLady\Downloads\tweets.zip
2013-08-20 17:53 - 2013-08-20 17:53 - 00012586 _____ C:\Users\LilLady\Desktop\Kündigung OZ.odt
2013-08-13 15:11 - 2013-08-13 15:11 - 00000000 ___DC C:\NvidiaLogging
==================== One Month Modified Files and Folders =======
2013-09-03 13:53 - 2013-09-03 13:53 - 00000618 _____ C:\Users\LilLady\Desktop\JRT.txt
2013-09-03 13:49 - 2013-09-03 13:49 - 00000000 ____D C:\WINDOWS\ERUNT
2013-09-03 13:48 - 2013-09-03 13:48 - 01028757 _____ (Thisisu) C:\Users\LilLady\Downloads\JRT.exe
2013-09-03 13:45 - 2013-09-03 11:06 - 00453529 _____ C:\WINDOWS\WindowsUpdate.log
2013-09-03 13:44 - 2013-08-30 13:56 - 00000000 ___DC C:\AdwCleaner
2013-09-03 13:37 - 2012-07-26 12:27 - 00714240 _____ C:\WINDOWS\system32\perfh007.dat
2013-09-03 13:37 - 2012-07-26 12:27 - 00147840 _____ C:\WINDOWS\system32\perfc007.dat
2013-09-03 13:37 - 2012-07-26 09:28 - 01654648 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-09-03 13:35 - 2013-09-03 13:35 - 01037134 _____ C:\Users\LilLady\Downloads\adwcleaner(1).exe
2013-09-03 13:33 - 2013-09-03 13:33 - 00000117 _____ C:\WINDOWS\system32\netcfg-37580.txt
2013-09-03 13:33 - 2013-09-03 11:50 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-03 13:33 - 2013-09-03 11:39 - 00000000 _____ C:\WINDOWS\system32\Drivers\lvuvc.hs
2013-09-03 13:33 - 2013-09-03 11:00 - 00001240 _____ C:\WINDOWS\PFRO.log
2013-09-03 13:33 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-09-03 13:32 - 2013-09-03 13:32 - 00000117 _____ C:\WINDOWS\system32\netcfg-4151171.txt
2013-09-03 13:24 - 2013-09-03 13:24 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\LilLady\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-03 13:24 - 2013-09-03 13:24 - 00001115 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-03 13:24 - 2013-09-03 13:24 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Malwarebytes
2013-09-03 13:24 - 2013-09-03 13:24 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-03 13:24 - 2013-09-03 13:24 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-03 13:20 - 2013-09-03 13:20 - 00004887 ____C C:\ComboFix.txt
2013-09-03 13:20 - 2012-07-26 07:37 - 00000000 __RHD C:\Users\Default
2013-09-03 13:20 - 2012-05-21 16:02 - 00000000 ____D C:\Qoobox
2013-09-03 13:17 - 2013-09-03 13:11 - 00000000 ____D C:\WINDOWS\erdnt
2013-09-03 13:17 - 2012-07-26 07:26 - 00000215 ____C C:\WINDOWS\system.ini
2013-09-03 13:11 - 2013-09-03 13:11 - 05119472 ____R (Swearware) C:\Users\LilLady\Downloads\ComboFix.exe
2013-09-03 13:11 - 2013-09-03 13:11 - 00000117 _____ C:\WINDOWS\system32\netcfg-2846690.txt
2013-09-03 13:11 - 2013-09-03 13:11 - 00000117 _____ C:\WINDOWS\system32\netcfg-2846628.txt
2013-09-03 13:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru
2013-09-03 12:45 - 2013-09-03 11:59 - 00000000 ___DC C:\Windows.old
2013-09-03 12:42 - 2013-09-03 11:49 - 00000000 ___DC C:\$SysReset
2013-09-03 12:42 - 2013-09-03 11:14 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-261323904-3986566715-3217930549-1001
2013-09-03 12:29 - 2013-09-03 12:29 - 00019402 _____ C:\Users\LilLady\Desktop\Addition.txt
2013-09-03 12:28 - 2013-09-03 12:28 - 00033116 _____ C:\Users\LilLady\Desktop\FRST.txt
2013-09-03 12:28 - 2013-09-03 12:28 - 00019402 _____ C:\Users\LilLady\Downloads\Addition.txt
2013-09-03 12:26 - 2013-09-03 12:26 - 00000000 ___DC C:\FRST
2013-09-03 12:26 - 2013-09-03 12:25 - 01950474 _____ (Farbar) C:\Users\LilLady\Downloads\FRST64.exe
2013-09-03 12:25 - 2013-09-03 12:25 - 00002067 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
2013-09-03 12:24 - 2013-09-03 12:24 - 00000117 _____ C:\WINDOWS\system32\netcfg-52057.txt
2013-09-03 12:24 - 2012-07-26 09:19 - 00307760 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-09-03 12:23 - 2013-09-03 12:23 - 00000117 _____ C:\WINDOWS\system32\netcfg-3890883.txt
2013-09-03 11:59 - 2013-09-03 11:59 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2013-09-03 11:59 - 2012-07-26 10:13 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2013-09-03 11:51 - 2013-09-03 11:51 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2013-09-03 11:51 - 2013-09-03 11:50 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2013-09-03 11:51 - 2013-09-03 11:48 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2013-09-03 11:50 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\Help
2013-09-03 11:49 - 2013-09-03 11:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2013-09-03 11:49 - 2011-06-26 14:59 - 00000000 ____D C:\Recovery
2013-09-03 11:46 - 2013-09-03 11:46 - 00003198 _____ C:\WINDOWS\System32\Tasks\{B18349A5-C633-4651-8AAA-2F98942E946D}
2013-09-03 11:46 - 2011-06-21 12:43 - 00000000 ____D C:\Users\LilLady\Desktop\Paint Shop Pro 7
2013-09-03 11:45 - 2013-09-03 11:34 - 00000000 ____D C:\Users\LilLady\AppData\Local\Adobe
2013-09-03 11:42 - 2013-09-03 11:39 - 00004869 _____ C:\WINDOWS\system32\lvcoinst.log
2013-09-03 11:42 - 2012-07-26 09:21 - 00019707 _____ C:\WINDOWS\setupact.log
2013-09-03 11:40 - 2013-09-03 11:39 - 00000000 ___SD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.0.0
2013-09-03 11:39 - 2013-09-03 11:39 - 00001188 _____ C:\Users\LilLady\Desktop\OpenOffice 4.0.0.lnk
2013-09-03 11:39 - 2013-09-03 11:39 - 00000000 ____D C:\Program Files\Common Files\logishrd
2013-09-03 11:39 - 2013-09-03 11:38 - 00000000 ____D C:\Program Files (x86)\OpenOffice 4
2013-09-03 11:36 - 2013-09-03 11:36 - 00000000 ____D C:\ProgramData\Adobe
2013-09-03 11:35 - 2013-09-03 11:21 - 450907216 _____ (G Data Software AG) C:\Users\LilLady\Downloads\GER_R_FUL_2013_IS.exe
2013-09-03 11:31 - 2013-09-03 11:31 - 00000000 ____D C:\Users\LilLady\Desktop\OpenOffice 4.0.0 (de) Installation Files
2013-09-03 11:31 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\restore
2013-09-03 11:31 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-09-03 11:24 - 2013-09-03 11:24 - 00000117 _____ C:\WINDOWS\system32\netcfg-365011.txt
2013-09-03 11:24 - 2013-09-03 11:24 - 00000117 _____ C:\WINDOWS\system32\netcfg-363123.txt
2013-09-03 11:24 - 2013-09-03 11:23 - 00001203 _____ C:\WINDOWS\system32\netcfg-347570.txt
2013-09-03 11:24 - 2013-09-03 11:23 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Mozilla
2013-09-03 11:23 - 2013-09-03 11:23 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\Users\LilLady\AppData\Local\Mozilla
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\ProgramData\Mozilla
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-03 11:23 - 2013-09-03 11:23 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-09-03 11:20 - 2013-09-03 11:20 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Macromedia
2013-09-03 11:19 - 2013-09-03 11:19 - 00000117 _____ C:\WINDOWS\system32\netcfg-51729.txt
2013-09-03 11:17 - 2013-09-03 11:17 - 00000117 _____ C:\WINDOWS\system32\netcfg-819036.txt
2013-09-03 11:17 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-09-03 11:09 - 2013-09-03 11:09 - 00024574 _____ C:\Users\LilLady\Desktop\Entfernte Anwendungen.html
2013-09-03 11:09 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-09-03 11:08 - 2013-09-03 11:08 - 00001444 _____ C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2013-09-03 11:08 - 2013-09-03 11:08 - 00000000 ___RD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-03 11:08 - 2013-09-03 11:08 - 00000000 ___RD C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2013-09-03 11:08 - 2013-09-03 11:08 - 00000000 ____D C:\Users\LilLady\AppData\Roaming\Adobe
2013-09-03 11:08 - 2013-09-03 11:05 - 00000000 ____D C:\Users\LilLady
2013-09-03 11:08 - 2013-06-08 18:15 - 00000000 ____D C:\Users\LilLady\AppData\Local\Packages
2013-09-03 11:07 - 2013-09-03 11:07 - 00000020 ___SH C:\Users\LilLady\ntuser.ini
2013-09-03 11:07 - 2013-09-03 11:07 - 00000000 ____D C:\Users\LilLady\AppData\Local\VirtualStore
2013-09-03 11:07 - 2013-09-03 11:07 - 00000000 ____D C:\ProgramData\PRICache
2013-09-03 11:07 - 2012-07-26 10:12 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2013-09-03 11:07 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\WinStore
2013-09-03 11:06 - 2013-09-03 11:50 - 00000000 ____D C:\WINDOWS\Panther
2013-09-03 11:06 - 2013-09-03 11:06 - 00000117 _____ C:\WINDOWS\system32\netcfg-128342.txt
2013-09-03 11:06 - 2013-09-03 11:06 - 00000117 _____ C:\WINDOWS\system32\netcfg-128264.txt
2013-09-03 11:06 - 2013-09-03 11:06 - 00000117 _____ C:\WINDOWS\system32\netcfg-128061.txt
2013-09-03 11:06 - 2013-09-03 11:06 - 00000000 ____D C:\WINDOWS\CSC
2013-09-03 11:06 - 2013-09-03 11:05 - 00000117 _____ C:\WINDOWS\system32\netcfg-124878.txt
2013-09-03 11:06 - 2012-12-18 18:53 - 00000000 ____D C:\Users\LilLady\Desktop\Seminare
2013-09-03 11:06 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\Recovery
2013-09-03 11:06 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\rescache
2013-09-03 11:06 - 2012-05-10 11:44 - 00000000 ____D C:\Users\LilLady\Desktop\Diverses
2013-09-03 11:05 - 2013-09-03 11:05 - 00017148 _____ C:\WINDOWS\diagwrn.xml
2013-09-03 11:05 - 2013-09-03 11:05 - 00017148 _____ C:\WINDOWS\diagerr.xml
2013-09-03 11:05 - 2013-09-03 11:05 - 00001139 _____ C:\WINDOWS\system32\netcfg-68765.txt
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Vorlagen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Startmenü
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Netzwerkumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Lokale Einstellungen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Eigene Dateien
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Druckumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Musik
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Eigene Bilder
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Verlauf
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Anwendungsdaten
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\UpdatusUser\Anwendungsdaten
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Vorlagen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Startmenü
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Netzwerkumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Lokale Einstellungen
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Eigene Dateien
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Druckumgebung
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Documents\Eigene Musik
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Documents\Eigene Bilder
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\AppData\Local\Verlauf
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\AppData\Local\Anwendungsdaten
2013-09-03 11:05 - 2013-09-03 11:05 - 00000000 _SHDL C:\Users\LilLady\Anwendungsdaten
2013-09-03 11:05 - 2012-07-26 10:12 - 00000000 __RHD C:\Users\Public\Libraries
2013-09-03 11:05 - 2009-07-14 20:18 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Musik
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Public\Documents\Eigene Bilder
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Vorlagen
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Startmenü
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Netzwerkumgebung
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Lokale Einstellungen
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Eigene Dateien
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Druckumgebung
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Musik
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Documents\Eigene Bilder
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\AppData\Local\Verlauf
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\AppData\Local\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Musik
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\Documents\Eigene Bilder
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Verlauf
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Vorlagen
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Startmenü
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Dokumente
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\ProgramData\Anwendungsdaten
2013-09-03 11:04 - 2013-09-03 11:04 - 00000000 _SHDL C:\Program Files\Gemeinsame Dateien
2013-09-03 11:04 - 2012-07-26 10:12 - 00000000 ____D C:\Program Files\Windows NT
2013-09-03 11:03 - 2012-07-26 10:13 - 00001720 _____ C:\WINDOWS\DtcInstall.log
2013-09-03 11:02 - 2013-09-03 11:02 - 00001134 _____ C:\WINDOWS\system32\netcfg-97719.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00001099 _____ C:\WINDOWS\system32\netcfg-130869.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000185 _____ C:\WINDOWS\system32\netcfg-108342.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000164 _____ C:\WINDOWS\system32\netcfg-101946.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000161 _____ C:\WINDOWS\system32\netcfg-104520.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-132117.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-104052.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-103069.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000160 _____ C:\WINDOWS\system32\netcfg-101541.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000159 _____ C:\WINDOWS\system32\netcfg-102648.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000157 _____ C:\WINDOWS\system32\netcfg-103584.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000157 _____ C:\WINDOWS\system32\netcfg-101182.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000150 _____ C:\WINDOWS\system32\netcfg-102274.txt
2013-09-03 11:02 - 2013-09-03 11:02 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2013-09-03 11:01 - 2013-09-03 11:01 - 00286200 _____ C:\WINDOWS\Minidump\090313-71479-01.dmp
2013-09-03 11:01 - 2013-09-03 11:01 - 00000000 ____D C:\WINDOWS\Minidump
2013-09-03 11:00 - 2013-09-03 11:00 - 268649420 _____ C:\WINDOWS\MEMORY.DMP
2013-08-30 14:49 - 2013-06-08 20:28 - 01918976 ___SH C:\Users\LilLady\Desktop\Thumbs.db
2013-08-30 14:43 - 2013-08-30 14:40 - 48494759 _____ C:\Users\LilLady\Documents\(5-5)ARD Der große Crash Die Wirtschaftskrise 1929 in Deutschland.flv
2013-08-30 14:21 - 2013-08-30 14:21 - 00804552 _____ (Koyote-Lab Inc.) C:\Users\LilLady\Downloads\FreeFLVConverter75Setup(1).exe
2013-08-30 14:14 - 2013-08-30 14:11 - 64915018 _____ C:\Users\LilLady\Documents\(2-5)ARD Der große Crash Die Wirtschaftskrise 1929 in Deutschland.flv
2013-08-30 14:13 - 2013-08-30 14:10 - 66620799 _____ C:\Users\LilLady\Documents\(1-5)ARD Der große Crash - Die Wirtschaftskrise 1929 in Deutschland.wmv.flv
2013-08-30 13:53 - 2013-08-30 13:53 - 00994642 _____ C:\Users\LilLady\Downloads\adwcleaner.exe
2013-08-29 12:05 - 2013-08-29 12:04 - 05843488 _____ (Mischel Internet Security ) C:\Users\LilLady\Downloads\TrojanHunterSetup_5.5_Build_1003.exe
2013-08-27 12:38 - 2012-12-18 18:53 - 00000000 ____D C:\Users\LilLady\Desktop\Schule
2013-08-27 11:52 - 2013-08-27 11:52 - 00004608 ___SH C:\Users\LilLady\Documents\Thumbs.db
2013-08-27 11:43 - 2013-08-27 11:43 - 11067384 _____ C:\Users\LilLady\Downloads\YTD43Setup.exe
2013-08-25 22:42 - 2013-08-25 22:42 - 00011229 _____ C:\Users\LilLady\Desktop\Unbenannt 2.odt
2013-08-25 14:05 - 2013-07-22 21:27 - 00017478 _____ C:\Users\LilLady\Desktop\Politik Reihenplanung Klasse 9 Sj 2013.odt
2013-08-24 12:15 - 2013-08-24 12:14 - 00000000 ____D C:\Users\Public\Documents\BitRaider
2013-08-24 12:12 - 2013-08-24 12:08 - 00014632 _____ C:\Users\LilLady\Documents\Install STAR WARS The Old Republic.log
2013-08-24 12:06 - 2013-08-24 12:06 - 39777624 _____ C:\Users\LilLady\Downloads\SWTOR_setup.exe
2013-08-20 18:46 - 2013-08-20 18:46 - 01681573 _____ C:\Users\LilLady\Downloads\tweets.zip
2013-08-20 17:53 - 2013-08-20 17:53 - 00012586 _____ C:\Users\LilLady\Desktop\Kündigung OZ.odt
2013-08-13 15:11 - 2013-08-13 15:11 - 00000000 ___DC C:\NvidiaLogging
Files to move or delete:
====================
C:\Users\LilLady\AppData\Local\Temp\jrt\erunt\ERUNT.EXE
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-03 11:00
==================== End Of Log ============================ --- --- ---
--- --- --- |