log vom mailwarebytes:
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.20.03
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
Frank :: ASUS-PC [Administrator]
20.09.2013 13:22:05
mbam-log-2013-09-20 (13-22-05).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 229309
Laufzeit: 7 Minute(n), 3 Sekunde(n)
Infizierte Speicherprozesse: 2
C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe (PUP.Optional.SoftwareUpdater.A) -> 732 -> Löschen bei Neustart.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-bg.exe (PUP.Optional.Lyrics.A) -> 7648 -> Löschen bei Neustart.
Infizierte Speichermodule: 1
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-bho.dll (PUP.Optional.Lyrics.A) -> Löschen bei Neustart.
Infizierte Registrierungsschlüssel: 18
HKLM\SYSTEM\CurrentControlSet\Services\SrvUpdater (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{11111111-1111-1111-1111-110411181168} (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\TypeLib\{44444444-4444-4444-4444-440444184468} (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\Interface\{55555555-5555-5555-5555-550455185568} (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CrossriderApp0041868.BHO.1 (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11111111-1111-1111-1111-110411181168} (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110411181168} (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110411181168} (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdater (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CrossriderApp0041868.BHO (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CrossriderApp0041868.Sandbox (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CrossriderApp0041868.Sandbox.1 (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\DEALPLY (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\InstalledBrowserExtensions\Lyrics (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\DEALPLY (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\SOFTWAREUPDATER (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DealPly (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Registrierungswerte: 4
HKCU\SOFTWARE\DealPly|Partner (PUP.Optional.DealPly.A) -> Daten: vita -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\DealPly|ChromeCrxPath (PUP.Optional.DealPly.A) -> Daten: C:\Program Files (x86)\DealPly\DealPly.crx -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\SoftwareUpdater|partner_keyword (PUP.Optional.SoftwareUpdater.A) -> Daten: EAZELDE -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SYSTEM\CurrentControlSet\Services\SrvUpdater|ImagePath (PUP.Optional.SoftwareUpdater.A) -> Daten: C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 5
C:\Program Files (x86)\DealPly (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater (PUP.Optional.SoftwareUpdater.A) -> Löschen bei Neustart.
C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly (PUP.OPtional.Dealply.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\DealPly (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\DealPly\UpdateProc (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 27
C:\Program Files (x86)\SoftwareUpdater\UpdaterService.exe (PUP.Optional.SoftwareUpdater.A) -> Löschen bei Neustart.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-bho.dll (PUP.Optional.Lyrics.A) -> Löschen bei Neustart.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-bho64.dll (PUP.Optional.Lyrics.A) -> Löschen bei Neustart.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-bg.exe (PUP.Optional.Lyrics.A) -> Löschen bei Neustart.
C:\$Recycle.Bin\S-1-5-21-348412604-1390753195-2502655749-1002\$R1GDFG0.exe (PUP.Optional.OpenCandy) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Local\Temp\instloffer.exe (PUP.Optional.VIT.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\Downloads\installer_magic_photo_editor_6_01_Deutsch.exe (PUP.Optional.VIT) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\DealPly.crx (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\DealPly.xpi (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\DealPlyIE64.dll (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\DealPlyUpdate.exe (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\DealPlyUpdateRun.exe (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\DealPlyUpdateVer.exe (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\icon.ico (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\DealPly\uninst.exe (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater\KeyGen.dll (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater\AppsUpdater.exe.config (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater\config.xml (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater\Interop.Shell32.dll (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater\translations.xml (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\SoftwareUpdater\uninstall.exe (PUP.Optional.SoftwareUpdater.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\Uninstall DealPly.lnk (PUP.OPtional.Dealply.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly Help.url (PUP.OPtional.Dealply.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DealPly\DealPly.url (PUP.OPtional.Dealply.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\DealPly\UpdateProc\config.dat (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\Frank\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe (PUP.Optional.DealPly.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.004 - Bericht erstellt am 20/09/2013 um 14:07:18
# Updated 15/09/2013 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Frank - ASUS-PC
# Gestartet von : C:\Users\Frank\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
Dienst Gelöscht : BackupStack
***** [ Dateien / Ordner ] *****
[#] Ordner Gelöscht : C:\Program Files (x86)\MyPC Backup
Ordner Gelöscht : C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyPC Backup
Ordner Gelöscht : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\Extensions\addon@dealplyshopping.com
Ordner Gelöscht : C:\Users\Frank\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojcgaoafcmbadjkfdippkdddgkeaipbn
Datei Gelöscht : C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Frank\Desktop\MyPC Backup.lnk
Datei Gelöscht : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\user.js
Datei Gelöscht : C:\WINDOWS\System32\Tasks\Dealply
Datei Gelöscht : C:\WINDOWS\System32\Tasks\DealPlyUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\InstalledBrowserExtensions
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16688
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\prefs.js ]
Zeile gelöscht : user_pref("browser.newtabpage.pinned", "[{\"url\":\"hxxp://www.dreamies.de/account.php\",\"title\":\"dreamies.de - Mein Account\"},null,{\"url\":\"hxxp://www.jappy.de/\",\"title\":\"Jappy - Deine Onli[...]
Zeile gelöscht : user_pref("extensions.crossrider.bic", "14136e2c20d4395fed8afb98c80fc56c");
Zeile gelöscht : user_pref("extensions.dealply.channel", "_vitaeazel");
*************************
AdwCleaner[R0].txt - [2374 octets] - [20/09/2013 13:59:22]
AdwCleaner[R1].txt - [2434 octets] - [20/09/2013 14:03:03]
AdwCleaner[S0].txt - [2144 octets] - [20/09/2013 14:07:18]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2204 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.1 (09.15.2013:1)
OS: Windows 8 x64
Ran by Frank on 20.09.2013 at 14:15:22,14
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
Failed to delete: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422182268}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466186668}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220422182268}
Failed to delete: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186668}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466186668}
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186668}
~~~ Files
Failed to delete: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-codedownloader.job
Failed to delete: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-enabler.job
Failed to delete: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-firefoxinstaller.job
Failed to delete: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-updater.job
~~~ Folders
Failed to delete: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted: [File] C:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\y2qbaotg.default\extensions\toolbar_avira-v7@apn.ask.com.xpi
Successfully deleted the following from C:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\y2qbaotg.default\prefs.js
user_pref("extensions.AVIRA-V7.com.avira.dnt.rules", "\"{\\\"Version\\\":38,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Anal
user_pref("extensions.AVIRA-V7.domain", "\"avira.search.ask.com\"");
Emptied folder: C:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\y2qbaotg.default\minidumps [13 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.09.2013 at 14:18:45,28
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-09-2013 01
Ran by Frank (administrator) on ASUS-PC on 20-09-2013 14:22:31
Running from C:\Users\Frank\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicShellService.exe
(Microsoft Corporation) C:\WINDOWS\system32\WLANExt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BBSvc.exe
(Microsoft Corporation) C:\WINDOWS\system32\dashost.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Key Suite\AsKeySuite.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Star Finanz - Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe
(TeamViewer GmbH) D:\Program Files (x86)\Tools\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Samsung) C:\Program Files (x86)\Samsung\PC Auto Backup\WiselinkPro.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
() C:\Program Files (x86)\Samsung\PC Auto Backup\http_ss_win_pro.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIHVE.EXE
(Samsung) C:\Program Files (x86)\Samsung\PC Auto Backup\AutoBackup.exe
() C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cashcrawler.exe
(Dropbox, Inc.) C:\Users\Frank\AppData\Roaming\Dropbox\bin\Dropbox.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(APN) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\ServiceLocator.exe
(APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Toolbar.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Adobe Systems, Inc.) C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\SeaPort.exe
(Microsoft Corporation) C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.2.9200.16613_none_6273bd8950d6cae2\TiWorker.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6839952 2012-09-13] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1218704 2012-09-26] (Realtek Semiconductor)
HKLM\...\Run: [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe [ ] ()
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\ScCertProp: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKCU\...\Run: [Device Detector] - DevDetect.exe -autorun
HKCU\...\Run: [Windows Remote Service] - D:\Program Files (x86)\Tools\Windows Remote Service\WindowsRemoteService.exe [173568 2013-05-24] (Banamalon)
HKCU\...\Run: [EPLTarget\P0000000000000002] - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIHVE.EXE [241280 2013-07-13] (SEIKO EPSON CORPORATION)
MountPoints2: {6e76d844-3ddb-11e2-be6a-806e6f6e6963} - "E:\Installer.exe"
MountPoints2: {93f7af59-14b1-11e3-be7d-08606e07ad67} - "I:\iLinker.exe"
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [277504 2012-07-09] (Intel Corporation)
HKLM-x32\...\Run: [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe [195200 2012-05-24] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [ASUSPRP] - C:\Program Files (x86)\ASUS\APRP\APRP.EXE [3187360 2012-11-08] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ASUS Ai Charger] - C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [IR_SERVER] - C:\PROGRA~1\Realtek\REALTE~1\IR_SERVER.exe [x]
HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-29] (CyberLink Corp.)
HKLM-x32\...\Run: [GrooveMonitor] - C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation)
HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-04] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [ApnTBMon] - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1558480 2013-07-26] (APN)
HKLM-x32\...\Run: [TrayServer] - D:\Program Files (x86)\MAGIX\Video_deluxe_17_Plus\TrayServer.exe [90112 2008-08-07] (MAGIX AG)
HKLM-x32\...\Run: [Ulead AutoDetector v2] - C:\Program Files (x86)\Common Files\Ulead Systems\AutoDetector\monitor.exe [90112 2004-11-26] (Ulead Systems, Inc.)
HKLM-x32\...\Run: [NeroFilterCheck] - C:\WINDOWS\system32\NeroCheck.exe [x]
HKLM-x32\...\Run: [InCD] - d:\Program Files (x86)\Ahead\InCD\InCD.exe [1237042 2003-12-05] (Ahead Software AG)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll,C:\PROGRA~2\NVIDIA~1\3DVISI~1\NVSTIN~1.DLL [18856 2012-10-02] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\3DVISI~1\nvStInit.dll [17288 2012-10-02] (NVIDIA Corporation)
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-13.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-14.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-16.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-18.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-19.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\2013-09-20.log ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cashcrawler.exe ()
Startup: C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Frank\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ASU2JS
BHO: LyricsBuddy-1 - {11111111-1111-1111-1111-110411181168} - C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-bho64.dll No File
BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
BHO-x32: Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
BHO-x32: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll (IvoSoft)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar plus Web Protection - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll (IvoSoft)
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GR469A~1.DLL [2210608 2006-10-27] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default
FF DefaultSearchEngine: benefind
FF SelectedSearchEngine: benefind
FF Homepage: hxxp://klamm.de
FF Plugin: @adobe.com/FlashPlayer - C:\WINDOWS\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\WINDOWS\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @TrendMicro.com/FFExtension - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\searchplugins\benefind.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: No Name - C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\Extensions\8af2e526-8c09-42dc-8d01-1001b936572c@5f890a75-ea43-44fa-9c15-0da08497ff9d.com
Chrome:
=======
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [815160 2013-09-04] (Avira Operations GmbH & Co. KG)
R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [168400 2013-07-26] (APN LLC.)
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe [149120 2012-02-17] (ASUSTeK Computer Inc.)
R2 ClassicShellService; C:\Program Files\Classic Shell\ClassicShellService.exe [68608 2013-06-29] (IvoSoft)
S2 InCDsrv; d:\Program Files (x86)\Ahead\InCD\InCDsrv.exe [798772 2003-12-05] (AHEAD Software)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-18] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [272176 2012-07-18] ()
R2 StarMoney 8.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 8.0 S-Edition\ouservice\StarMoneyOnlineUpdate.exe [699680 2012-12-21] (Star Finanz - Software Entwicklung und Vertriebs GmbH)
R2 TeamViewer8; D:\Program Files (x86)\Tools\TeamViewer_Service.exe [5071712 2013-09-02] (TeamViewer GmbH)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
R2 WiselinkPro; C:\Program Files (x86)\Samsung\PC Auto Backup\WiselinkPro.exe [7262263 2012-01-06] (Samsung)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2699568 2012-07-18] (Intel® Corporation)
==================== Drivers (Whitelisted) ====================
R3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-23] (ASUSTek Computer Inc.)
R3 AiCharger; C:\Windows\SysWow64\drivers\AiCharger.sys [14848 2012-03-23] (ASUSTek Computer Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2010-08-03] ()
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132088 2013-09-04] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-07-14] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [82136 2013-09-04] (Avira Operations GmbH & Co. KG)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [4273192 2012-08-08] (Intel Corporation)
R3 S332x64; C:\Windows\system32\DRIVERS\S332x64.sys [78080 2012-02-27] (Identive )
S3 SPR132; C:\Windows\SysWow64\DRIVERS\SPR132.sys [181504 2003-10-10] (SCM Microsystems Inc.)
S3 SPRx32 USB Smart Card Reader; C:\Windows\SysWow64\DRIVERS\SPR332.sys [63252 2003-10-13] (SCM Microsystems Inc.)
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [47072 2012-11-29] (Windows (R) Win 7 DDK provider)
R3 XHCIPort; C:\Windows\System32\drivers\XHCIPort.sys [188896 2012-10-10] (Windows (R) Win 7 DDK provider)
S4 InCDfs; No ImagePath
S1 InCDPass; System32\DRIVERS\InCDPass.sys [x]
U1 InCDrec; No ImagePath
S3 SPR132; \SystemRoot\system32\DRIVERS\SPR132.sys [x]
S3 SPRx32 USB Smart Card Reader; \SystemRoot\system32\DRIVERS\SPR332.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-09-20 14:18 - 2013-09-20 14:18 - 00003081 _____ C:\Users\Frank\Desktop\JRT.txt
2013-09-20 14:15 - 2013-09-20 14:15 - 00000000 ____D C:\WINDOWS\ERUNT
2013-09-20 13:58 - 2013-09-20 14:07 - 00000000 ____D C:\AdwCleaner
2013-09-20 13:43 - 2013-09-20 13:43 - 01029675 _____ (Thisisu) C:\Users\Frank\Downloads\JRT.exe
2013-09-20 13:19 - 2013-09-20 13:19 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Malwarebytes
2013-09-20 13:18 - 2013-09-20 13:18 - 00001116 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-20 13:18 - 2013-09-20 13:18 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-20 13:18 - 2013-09-20 13:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-20 13:18 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2013-09-20 13:10 - 2013-09-20 13:10 - 01039554 _____ C:\Users\Frank\Downloads\adwcleaner.exe
2013-09-20 13:09 - 2013-09-20 13:10 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Frank\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-20 10:28 - 2013-09-20 10:28 - 00002132 _____ C:\Users\Public\Desktop\PC Auto Backup.lnk
2013-09-20 09:50 - 2013-09-20 09:51 - 00035909 _____ C:\Users\Frank\Downloads\Addition.txt
2013-09-20 09:48 - 2013-09-20 09:48 - 00000000 ____D C:\FRST
2013-09-20 09:47 - 2013-09-20 09:47 - 01950622 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe
2013-09-19 18:58 - 2013-09-19 19:02 - 00000000 ____D C:\Users\Frank\Documents\Intelli-studio
2013-09-19 18:43 - 2013-09-19 18:43 - 33597582 _____ (Samsung Electronics Co,. Ltd.) C:\Users\Frank\Downloads\PCAutoBackup_setup.exe
2013-09-19 18:39 - 2013-09-19 19:02 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Intelli-studio
2013-09-19 17:41 - 2013-09-20 14:09 - 00001318 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-updater.job
2013-09-19 17:41 - 2013-09-20 14:08 - 00001222 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-codedownloader.job
2013-09-19 17:41 - 2013-09-20 14:08 - 00001122 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-enabler.job
2013-09-19 17:41 - 2013-09-19 17:41 - 00004322 _____ C:\WINDOWS\System32\Tasks\LyricsBuddy-1-updater
2013-09-19 17:41 - 2013-09-19 17:41 - 00004226 _____ C:\WINDOWS\System32\Tasks\LyricsBuddy-1-codedownloader
2013-09-19 17:41 - 2013-09-19 17:41 - 00004126 _____ C:\WINDOWS\System32\Tasks\LyricsBuddy-1-enabler
2013-09-19 17:40 - 2013-09-20 14:08 - 00001858 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-firefoxinstaller.job
2013-09-19 17:40 - 2013-09-20 13:55 - 00000000 ____D C:\Program Files (x86)\LyricsBuddy-1
2013-09-18 11:42 - 2013-09-18 11:42 - 00548792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-09-13 13:56 - 2013-09-13 13:56 - 00002040 _____ C:\Users\Public\Desktop\PDF erstellen.lnk
2013-09-13 13:56 - 2013-09-13 13:56 - 00000000 ____D C:\Program Files\CIB software GmbH
2013-09-13 13:43 - 2013-09-13 13:43 - 25506456 _____ (CIB software GmbH ) C:\Users\Frank\Downloads\cibpdfbrewer-x64.exe
2013-09-13 13:36 - 2013-09-13 13:36 - 00000000 ____D C:\Users\Frank\AppData\Roaming\WordToPDF Pro
2013-09-13 13:34 - 2013-09-13 13:34 - 01610339 _____ (Mario Noack ) C:\Users\Frank\Downloads\SetupWordToPDF_Pro_237.exe
2013-09-12 11:53 - 2013-09-12 13:03 - 00000000 ____D C:\Users\Frank\AppData\Roaming\TeamViewer
2013-09-12 11:50 - 2013-09-12 11:50 - 00000750 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-09-12 11:48 - 2013-09-12 11:48 - 05829952 _____ (TeamViewer GmbH) C:\Users\Frank\Downloads\TeamViewer_Setup_de_8.0.20768.exe
2013-09-12 10:40 - 2013-09-12 10:40 - 00002026 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-09-12 10:39 - 2013-09-12 10:39 - 00000000 ____D C:\Users\Frank\Documents\PDF-Dateien
2013-09-12 10:39 - 2002-10-30 19:12 - 00106496 ____N (FinePrint Software, LLC) C:\WINDOWS\SysWOW64\fppr132.dll
2013-09-12 10:39 - 2002-10-30 17:02 - 00225280 ____N (FinePrint Software, LLC) C:\WINDOWS\SysWOW64\fppmon1.dll
2013-09-12 08:50 - 2013-08-21 06:12 - 02241024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-09-12 08:50 - 2013-08-21 06:12 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-09-12 08:50 - 2013-08-21 06:11 - 19246592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 15404544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2013-09-12 08:50 - 2013-08-21 06:11 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2013-09-12 08:50 - 2013-08-21 04:34 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2013-09-12 08:50 - 2013-08-21 04:06 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-09-12 08:50 - 2013-08-21 04:06 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-09-12 08:50 - 2013-08-21 04:06 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 14332928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 13761024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 02048000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2013-09-12 08:50 - 2013-08-21 04:05 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2013-09-12 08:50 - 2013-08-21 03:43 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2013-09-12 08:50 - 2013-08-21 01:52 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2013-09-12 08:50 - 2013-08-16 07:41 - 00058200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2013-09-12 08:50 - 2013-08-16 07:39 - 02371728 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2013-09-12 08:50 - 2013-08-16 07:39 - 00059416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2013-09-12 08:50 - 2013-08-16 07:32 - 00209200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationUI.exe
2013-09-12 08:50 - 2013-08-16 07:22 - 04917760 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2013-09-12 08:50 - 2013-08-16 07:22 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2013-09-12 08:50 - 2013-08-16 07:21 - 03275776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 01621504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00688640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSClient.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppc.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupcln.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2013-09-12 08:50 - 2013-08-16 07:21 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2013-09-12 08:50 - 2013-08-16 07:20 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00562688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSClient.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00126976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00083968 _____ C:\WINDOWS\SysWOW64\OEMLicense.dll
2013-09-12 08:50 - 2013-08-16 00:43 - 00035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2013-09-12 08:50 - 2013-08-16 00:43 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2013-09-12 08:50 - 2013-08-16 00:42 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppc.dll
2013-09-12 08:50 - 2013-08-16 00:42 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupcln.dll
2013-09-12 08:50 - 2013-08-03 06:30 - 04038144 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2013-09-12 08:50 - 2013-07-09 10:04 - 00120144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2013-09-12 08:50 - 2013-07-09 08:18 - 00439488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2013-09-12 08:50 - 2013-07-09 06:25 - 00385768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2013-09-12 08:50 - 2013-07-09 05:57 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LocationApi.dll
2013-09-12 08:50 - 2013-07-09 00:46 - 00543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2013-09-12 08:50 - 2013-07-09 00:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2013-09-12 08:50 - 2013-07-09 00:46 - 00370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanadvui.dll
2013-09-12 08:50 - 2013-07-09 00:45 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationApi.dll
2013-09-12 08:50 - 2013-07-06 02:16 - 01025024 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2013-09-12 08:50 - 2013-07-03 02:23 - 00778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2013-09-12 08:50 - 2013-07-03 02:23 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2013-09-12 08:50 - 2013-07-03 02:22 - 02839552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2013-09-12 08:50 - 2013-07-03 02:22 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2013-09-12 08:50 - 2013-07-03 02:11 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2013-09-12 08:50 - 2013-07-03 02:11 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2013-09-12 08:50 - 2013-07-03 02:10 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2013-09-12 08:50 - 2013-07-02 00:08 - 00387583 _____ C:\WINDOWS\system32\ApnDatabase.xml
2013-09-12 08:50 - 2013-07-01 00:30 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\openfiles.exe
2013-09-12 08:50 - 2013-07-01 00:29 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\openfiles.exe
2013-09-12 08:50 - 2013-06-29 08:15 - 00195416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2013-09-12 08:50 - 2013-06-29 08:15 - 00125784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2013-09-12 08:50 - 2013-06-29 07:43 - 00327512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2013-09-12 08:50 - 2013-06-29 03:12 - 01022464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2013-09-12 08:50 - 2013-06-26 05:01 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2013-09-12 08:50 - 2013-06-26 04:59 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\HdAudio.sys
2013-09-12 08:50 - 2013-06-25 00:54 - 00447488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2013-09-12 08:50 - 2013-06-25 00:54 - 00263680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2013-09-12 08:50 - 2013-06-25 00:54 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2013-09-12 08:50 - 2013-06-19 07:36 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmmbase.dll
2013-09-12 08:50 - 2013-06-19 07:36 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmm.dll
2013-09-12 08:50 - 2013-06-19 00:38 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmmbase.dll
2013-09-12 08:50 - 2013-06-19 00:38 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmm.dll
2013-09-12 08:50 - 2013-06-12 01:43 - 00154112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
2013-09-12 08:50 - 2013-06-12 01:26 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
2013-09-12 08:50 - 2013-06-10 23:17 - 00096512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2013-09-12 08:50 - 2013-06-10 21:16 - 00888832 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2013-09-12 08:50 - 2013-06-10 21:15 - 01156096 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2013-09-12 08:50 - 2013-06-10 21:15 - 00723968 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2013-09-12 08:50 - 2013-06-10 21:15 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2013-09-12 08:50 - 2013-06-10 21:10 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2013-09-12 08:50 - 2013-06-10 21:10 - 00245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2013-09-12 08:50 - 2013-06-06 10:03 - 00119040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2013-09-07 17:47 - 2013-09-12 10:18 - 97124766 _____ C:\WINDOWS\SysWOW64\᯾瞜ϸ¿߿
2013-09-06 14:02 - 2013-09-06 14:02 - 00867240 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\npDeployJava1.dll
2013-09-06 14:02 - 2013-09-06 14:02 - 00789416 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\deployJava1.dll
2013-09-06 14:02 - 2013-09-06 14:02 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2013-09-06 14:02 - 2013-09-06 14:02 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2013-09-06 14:02 - 2013-09-06 14:02 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2013-09-06 14:02 - 2013-09-06 14:02 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2013-09-06 14:02 - 2013-09-06 14:02 - 00000000 ____D C:\ProgramData\Sun
2013-09-06 14:02 - 2013-09-06 14:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-06 13:57 - 2013-09-06 13:57 - 00903080 _____ (Oracle Corporation) C:\Users\Frank\Downloads\jxpiinstall.exe
2013-09-06 13:56 - 2013-09-06 14:04 - 00000000 ____D C:\Users\Frank\Downloads\jameica-win64
2013-09-06 13:54 - 2013-09-06 13:55 - 12812027 _____ C:\Users\Frank\Downloads\jameica-win64.zip
2013-09-06 12:34 - 2013-09-06 12:34 - 00000000 ____D C:\Users\Frank\Downloads\jverein.2.4.2
2013-09-06 10:09 - 2013-09-06 10:09 - 02843524 _____ C:\Users\Frank\Downloads\jverein.2.4.2.zip
2013-09-04 19:36 - 2013-09-06 18:28 - 96334488 _____ C:\WINDOWS\SysWOW64\᯾瞠宀Ń߿
2013-08-30 19:59 - 2013-08-30 19:59 - 00000000 ____D C:\WINDOWS\SysWOW64\CSP
2013-08-30 19:59 - 2013-08-30 19:59 - 00000000 ____D C:\Users\RYU
2013-08-30 19:59 - 2013-08-30 19:59 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-08-30 19:38 - 2013-09-19 18:40 - 00001030 _____ C:\Users\Public\Desktop\Intelli-studio.lnk
2013-08-22 10:55 - 2013-08-22 10:55 - 00101495 _____ C:\Users\Frank\Downloads\benefind_logos.zip
2013-08-21 11:56 - 2013-08-21 11:56 - 16218912 _____ (Canonical) C:\Users\Frank\Downloads\ubuntuone-4.1.91.1-windows-installer.exe
==================== One Month Modified Files and Folders =======
2013-09-20 14:22 - 2012-12-04 08:31 - 01486348 _____ C:\WINDOWS\WindowsUpdate.log
2013-09-20 14:18 - 2013-09-20 14:18 - 00003081 _____ C:\Users\Frank\Desktop\JRT.txt
2013-09-20 14:16 - 2012-11-08 05:31 - 00756440 _____ C:\WINDOWS\system32\perfh007.dat
2013-09-20 14:16 - 2012-11-08 05:31 - 00157166 _____ C:\WINDOWS\system32\perfc007.dat
2013-09-20 14:16 - 2012-07-26 09:28 - 01757438 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2013-09-20 14:15 - 2013-09-20 14:15 - 00000000 ____D C:\WINDOWS\ERUNT
2013-09-20 14:14 - 2013-07-13 19:09 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-348412604-1390753195-2502655749-1002
2013-09-20 14:10 - 2013-08-02 11:44 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Dropbox
2013-09-20 14:09 - 2013-09-19 17:41 - 00001318 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-updater.job
2013-09-20 14:08 - 2013-09-19 17:41 - 00001222 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-codedownloader.job
2013-09-20 14:08 - 2013-09-19 17:41 - 00001122 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-enabler.job
2013-09-20 14:08 - 2013-09-19 17:40 - 00001858 _____ C:\WINDOWS\Tasks\LyricsBuddy-1-firefoxinstaller.job
2013-09-20 14:08 - 2012-12-04 08:31 - 00000000 ____D C:\ProgramData\NVIDIA
2013-09-20 14:08 - 2012-07-26 09:22 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2013-09-20 14:07 - 2013-09-20 13:58 - 00000000 ____D C:\AdwCleaner
2013-09-20 14:07 - 2013-07-13 19:01 - 00000000 ___RD C:\Users\Frank\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2013-09-20 14:07 - 2012-07-26 07:26 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2013-09-20 14:00 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\sru
2013-09-20 13:55 - 2013-09-19 17:40 - 00000000 ____D C:\Program Files (x86)\LyricsBuddy-1
2013-09-20 13:55 - 2012-11-08 06:15 - 01015060 _____ C:\WINDOWS\PFRO.log
2013-09-20 13:43 - 2013-09-20 13:43 - 01029675 _____ (Thisisu) C:\Users\Frank\Downloads\JRT.exe
2013-09-20 13:40 - 2013-07-14 08:48 - 00000884 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2013-09-20 13:19 - 2013-09-20 13:19 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Malwarebytes
2013-09-20 13:18 - 2013-09-20 13:18 - 00001116 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-09-20 13:18 - 2013-09-20 13:18 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-09-20 13:18 - 2013-09-20 13:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-09-20 13:10 - 2013-09-20 13:10 - 01039554 _____ C:\Users\Frank\Downloads\adwcleaner.exe
2013-09-20 13:10 - 2013-09-20 13:09 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Frank\Downloads\mbam-setup-1.75.0.1300.exe
2013-09-20 12:34 - 2013-07-16 12:39 - 00000000 ____D C:\Program Files (x86)\StarMoney 8.0 S-Edition
2013-09-20 10:28 - 2013-09-20 10:28 - 00002132 _____ C:\Users\Public\Desktop\PC Auto Backup.lnk
2013-09-20 10:28 - 2012-11-08 06:28 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-09-20 09:51 - 2013-09-20 09:50 - 00035909 _____ C:\Users\Frank\Downloads\Addition.txt
2013-09-20 09:48 - 2013-09-20 09:48 - 00000000 ____D C:\FRST
2013-09-20 09:47 - 2013-09-20 09:47 - 01950622 _____ (Farbar) C:\Users\Frank\Downloads\FRST64.exe
2013-09-20 06:40 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2013-09-19 19:02 - 2013-09-19 18:58 - 00000000 ____D C:\Users\Frank\Documents\Intelli-studio
2013-09-19 19:02 - 2013-09-19 18:39 - 00000000 ____D C:\Users\Frank\AppData\Roaming\Intelli-studio
2013-09-19 18:43 - 2013-09-19 18:43 - 33597582 _____ (Samsung Electronics Co,. Ltd.) C:\Users\Frank\Downloads\PCAutoBackup_setup.exe
2013-09-19 18:40 - 2013-08-30 19:38 - 00001030 _____ C:\Users\Public\Desktop\Intelli-studio.lnk
2013-09-19 18:12 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2013-09-19 17:41 - 2013-09-19 17:41 - 00004322 _____ C:\WINDOWS\System32\Tasks\LyricsBuddy-1-updater
2013-09-19 17:41 - 2013-09-19 17:41 - 00004226 _____ C:\WINDOWS\System32\Tasks\LyricsBuddy-1-codedownloader
2013-09-19 17:41 - 2013-09-19 17:41 - 00004126 _____ C:\WINDOWS\System32\Tasks\LyricsBuddy-1-enabler
2013-09-19 17:41 - 2013-07-26 13:08 - 00000000 ____D C:\Users\Frank\AppData\Local\Google
2013-09-19 17:13 - 2013-07-18 10:29 - 00014848 _____ C:\Users\Frank\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-09-19 13:44 - 2013-07-21 12:42 - 00000000 ____D C:\Users\Frank\Documents\Turbo Lister Backup
2013-09-19 09:14 - 2013-07-17 09:45 - 00000000 ____D C:\Users\Frank\Documents\1 Exel Tabellen
2013-09-18 17:38 - 2013-08-15 17:33 - 00000000 ____D C:\Users\Frank\MEDION NAS TOOL
2013-09-18 17:28 - 2012-07-26 09:21 - 00022823 _____ C:\WINDOWS\setupact.log
2013-09-18 11:42 - 2013-09-18 11:42 - 00548792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2013-09-18 09:03 - 2013-07-21 11:40 - 00000000 ____D C:\Users\Frank\Documents\2013
2013-09-16 13:19 - 2013-07-14 07:25 - 00000000 ____D C:\Users\Frank\AppData\Local\Windows Live
2013-09-15 13:37 - 2013-07-21 12:43 - 00000000 ____D C:\Users\Frank\Documents\PDF
2013-09-14 17:16 - 2013-07-18 11:50 - 00243200 ___SH C:\Users\Frank\Downloads\Thumbs.db
2013-09-14 12:43 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\rescache
2013-09-13 13:56 - 2013-09-13 13:56 - 00002040 _____ C:\Users\Public\Desktop\PDF erstellen.lnk
2013-09-13 13:56 - 2013-09-13 13:56 - 00000000 ____D C:\Program Files\CIB software GmbH
2013-09-13 13:46 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\WinStore
2013-09-13 13:46 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2013-09-13 13:46 - 2012-07-26 07:38 - 00000000 ____D C:\WINDOWS\system32\oobe
2013-09-13 13:43 - 2013-09-13 13:43 - 25506456 _____ (CIB software GmbH ) C:\Users\Frank\Downloads\cibpdfbrewer-x64.exe
2013-09-13 13:43 - 2013-07-18 08:50 - 00000000 ____D C:\Users\Frank\AppData\Local\Downloaded Installations
2013-09-13 13:36 - 2013-09-13 13:36 - 00000000 ____D C:\Users\Frank\AppData\Roaming\WordToPDF Pro
2013-09-13 13:34 - 2013-09-13 13:34 - 01610339 _____ (Mario Noack ) C:\Users\Frank\Downloads\SetupWordToPDF_Pro_237.exe
2013-09-13 12:42 - 2013-07-15 08:54 - 1225081856 _____ C:\Users\Public\Documents\2013_07_outlook_komplett.pst
2013-09-13 12:12 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\system32\NDF
2013-09-12 13:03 - 2013-09-12 11:53 - 00000000 ____D C:\Users\Frank\AppData\Roaming\TeamViewer
2013-09-12 12:45 - 2013-07-15 11:24 - 00165984 _____ C:\Users\Frank\AppData\Local\GDIPFONTCACHEV1.DAT
2013-09-12 11:50 - 2013-09-12 11:50 - 00000750 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
2013-09-12 11:48 - 2013-09-12 11:48 - 05829952 _____ (TeamViewer GmbH) C:\Users\Frank\Downloads\TeamViewer_Setup_de_8.0.20768.exe
2013-09-12 10:40 - 2013-09-12 10:40 - 00002026 _____ C:\Users\Public\Desktop\Adobe Reader X.lnk
2013-09-12 10:39 - 2013-09-12 10:39 - 00000000 ____D C:\Users\Frank\Documents\PDF-Dateien
2013-09-12 10:18 - 2013-09-07 17:47 - 97124766 _____ C:\WINDOWS\SysWOW64\᯾瞜ϸ¿߿
2013-09-12 09:16 - 2013-07-19 10:25 - 00000000 ____D C:\WINDOWS\system32\MRT
2013-09-12 09:13 - 2013-07-14 08:53 - 79143768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2013-09-11 08:40 - 2013-07-14 08:48 - 00003772 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2013-09-09 17:34 - 2013-07-17 18:32 - 00000000 ____D C:\Users\Frank\Documents\BVB
2013-09-09 10:25 - 2013-07-21 11:27 - 00000000 ____D C:\Users\Frank\Documents\Blankenburg
2013-09-07 17:45 - 2013-07-14 07:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-09-06 18:28 - 2013-09-04 19:36 - 96334488 _____ C:\WINDOWS\SysWOW64\᯾瞠宀Ń߿
2013-09-06 14:04 - 2013-09-06 13:56 - 00000000 ____D C:\Users\Frank\Downloads\jameica-win64
2013-09-06 14:02 - 2013-09-06 14:02 - 00867240 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\npDeployJava1.dll
2013-09-06 14:02 - 2013-09-06 14:02 - 00789416 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\deployJava1.dll
2013-09-06 14:02 - 2013-09-06 14:02 - 00263592 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2013-09-06 14:02 - 2013-09-06 14:02 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2013-09-06 14:02 - 2013-09-06 14:02 - 00175016 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2013-09-06 14:02 - 2013-09-06 14:02 - 00096168 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2013-09-06 14:02 - 2013-09-06 14:02 - 00000000 ____D C:\ProgramData\Sun
2013-09-06 14:02 - 2013-09-06 14:02 - 00000000 ____D C:\Program Files (x86)\Java
2013-09-06 13:57 - 2013-09-06 13:57 - 00903080 _____ (Oracle Corporation) C:\Users\Frank\Downloads\jxpiinstall.exe
2013-09-06 13:55 - 2013-09-06 13:54 - 12812027 _____ C:\Users\Frank\Downloads\jameica-win64.zip
2013-09-06 12:34 - 2013-09-06 12:34 - 00000000 ____D C:\Users\Frank\Downloads\jverein.2.4.2
2013-09-06 10:09 - 2013-09-06 10:09 - 02843524 _____ C:\Users\Frank\Downloads\jverein.2.4.2.zip
2013-09-05 22:09 - 2012-07-26 10:14 - 00694232 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2013-09-05 22:09 - 2012-07-26 10:14 - 00078296 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2013-09-04 13:38 - 2013-07-14 18:33 - 00132088 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2013-09-04 13:38 - 2013-07-14 18:33 - 00105344 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2013-09-04 13:38 - 2013-07-14 18:33 - 00082136 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2013-09-01 11:57 - 2013-07-20 11:50 - 00000784 _____ C:\Users\Frank\Documents\1gb.txt
2013-08-30 19:59 - 2013-08-30 19:59 - 00000000 ____D C:\WINDOWS\SysWOW64\CSP
2013-08-30 19:59 - 2013-08-30 19:59 - 00000000 ____D C:\Users\RYU
2013-08-30 19:59 - 2013-08-30 19:59 - 00000000 ____D C:\Program Files (x86)\Samsung
2013-08-22 10:55 - 2013-08-22 10:55 - 00101495 _____ C:\Users\Frank\Downloads\benefind_logos.zip
2013-08-21 11:56 - 2013-08-21 11:56 - 16218912 _____ (Canonical) C:\Users\Frank\Downloads\ubuntuone-4.1.91.1-windows-installer.exe
2013-08-21 06:12 - 2013-09-12 08:50 - 02241024 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2013-08-21 06:12 - 2013-09-12 08:50 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2013-08-21 06:11 - 2013-09-12 08:50 - 19246592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 15404544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 03959296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 01365504 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesysprep.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\UXInit.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2013-08-21 06:11 - 2013-09-12 08:50 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2013-08-21 04:34 - 2013-09-12 08:50 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2013-08-21 04:06 - 2013-09-12 08:50 - 01767936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2013-08-21 04:06 - 2013-09-12 08:50 - 01141248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2013-08-21 04:06 - 2013-09-12 08:50 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UXInit.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 14332928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 13761024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 02876928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 02048000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 00493056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesysprep.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 00039936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2013-08-21 04:05 - 2013-09-12 08:50 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2013-08-21 03:43 - 2013-09-12 08:50 - 02706432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2013-08-21 01:52 - 2013-09-12 08:50 - 00534528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
Some content of TEMP:
====================
C:\Users\Frank\AppData\Local\Temp\79515-663724-magic-photo-editor.exe
C:\Users\Frank\AppData\Local\Temp\BackupSetup.exe
C:\Users\Frank\AppData\Local\Temp\COMAP.EXE
C:\Users\Frank\AppData\Local\Temp\ose00000.exe
C:\Users\Frank\AppData\Local\Temp\Quarantine.exe
C:\Users\Frank\AppData\Local\Temp\vcredist_x64.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-09-19 11:59
==================== End Of Log ============================
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
im moment ist die werbung noch nicht weg... :-(
ich hatte nur den schnellen suchlauf mit mailwarebytes gewählt, ein fehler?
nun mit ausführlichem scan
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2013.09.20.03
Windows 8 x64 NTFS
Internet Explorer 10.0.9200.16688
Frank :: ASUS-PC [Administrator]
20.09.2013 16:36:11
mbam-log-2013-09-20 (16-36-11).txt
Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 540731
Laufzeit: 1 Stunde(n), 26 Minute(n), 4 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Dateien: 8
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\APNSetup.exe (PUP.Optional.ASKToolbar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-buttonutil.exe (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-buttonutil64.exe (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-codedownloader.exe (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-enabler.exe (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-firefoxinstaller.exe (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\LyricsBuddy-1-updater.exe (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Program Files (x86)\LyricsBuddy-1\utils.exe (PUP.Optional.Lyrics.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.004 - Bericht erstellt am 20/09/2013 um 18:15:01
# Updated 15/09/2013 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Frank - ASUS-PC
# Gestartet von : C:\Users\Frank\Downloads\adwcleaner.exe
# Option : Suchen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16688
-\\ Mozilla Firefox v23.0.1 (de)
[ Datei : C:\Users\Frank\AppData\Roaming\Mozilla\Firefox\Profiles\y2qbaotg.default\prefs.js ]
*************************
AdwCleaner[R0].txt - [2374 octets] - [20/09/2013 13:59:22]
AdwCleaner[R1].txt - [2434 octets] - [20/09/2013 14:03:03]
AdwCleaner[R2].txt - [756 octets] - [20/09/2013 18:15:01]
AdwCleaner[S0].txt - [2284 octets] - [20/09/2013 14:07:18]
########## EOF - C:\AdwCleaner\AdwCleaner[R2].txt - [875 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.0.1 (09.15.2013:1)
OS: Windows 8 x64
Ran by Frank on 20.09.2013 at 18:19:04,10
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully deleted: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\apntbmon
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\App Paths\mypc backup
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220422182268}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660466186668}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{22222222-2222-2222-2222-220422182268}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186668}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660466186668}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\Interface\{66666666-6666-6666-6666-660466186668}
~~~ Files
Successfully deleted: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-codedownloader.job
Successfully deleted: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-enabler.job
Successfully deleted: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-firefoxinstaller.job
Successfully deleted: [File] C:\WINDOWS\Tasks\LyricsBuddy-1-updater.job
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
~~~ FireFox
Successfully deleted the following from C:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\y2qbaotg.default\prefs.js
user_pref("extensions.AVIRA-V7.com.avira.dnt.rules", "\"{\\\"Version\\\":38,\\\"Companies\\\":[{\\\"company\\\":\\\"Google Inc\\\",\\\"rules\\\":[{\\\"name\\\":\\\"Google Anal
user_pref("extensions.AVIRA-V7.domain", "\"avira.search.ask.com\"");
Emptied folder: C:\Users\Frank\AppData\Roaming\mozilla\firefox\profiles\y2qbaotg.default\minidumps [3 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.09.2013 at 18:22:52,32
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~