Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Datenbank Version: v2014.02.05.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
WasensteinerBenedikt :: WASENSTEINERBEN [Administrator]
05.02.2014 10:27:07
mbam-log-2014-02-05 (10-27-07).txt
Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM | P2P
Deaktivierte Suchlaufeinstellungen:
Durchsuchte Objekte: 211206
Laufzeit: 4 Minute(n), 46 Sekunde(n)
Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule: 1
C:\Users\WasensteinerBenedikt\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Löschen bei Neustart.
Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NextLive (PUP.Optional.NextLive.A) -> Daten: C:\Windows\SysWOW64\rundll32.exe "C:\Users\WasensteinerBenedikt\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse: 4
C:\Users\WasensteinerBenedikt\AppData\Roaming\newnext.me (PUP.Optional.NextLive.A) -> Löschen bei Neustart.
C:\Users\WasensteinerBenedikt\AppData\Roaming\newnext.me\cache (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\WasensteinerBenedikt\AppData\Local\Google\Chrome\User Data\Default\Extensions\koaigfekcaicjopbdljgmcmcmbmeadop (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\WasensteinerBenedikt\AppData\Local\Google\Chrome\User Data\Default\Extensions\koaigfekcaicjopbdljgmcmcmbmeadop\1.26.70_0 (PUP.Optional.CrossRider.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
Infizierte Dateien: 5
C:\Users\WasensteinerBenedikt\AppData\Roaming\newnext.me\nengine.dll (PUP.Optional.NextLive.A) -> Löschen bei Neustart.
C:\ProgramData\YTD Video Downloader\ytd_installer.exe (PUP.Optional.Spigot.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\WasensteinerBenedikt\AppData\Local\genienext\nengine.dll (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\WasensteinerBenedikt\AppData\Roaming\newnext.me\nengine.cookie (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\Users\WasensteinerBenedikt\AppData\Roaming\newnext.me\cache\spark.bin (PUP.Optional.NextLive.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
(Ende)AdwCleaner Logfile:
Code:
# AdwCleaner v3.018 - Bericht erstellt am 05/02/2014 um 10:42:05
# Updated 28/01/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : WasensteinerBenedikt - WASENSTEINERBEN
# Gestartet von : D:\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16428
-\\ Mozilla Firefox v25.0.1 (de)
[ Datei : C:\Users\WasensteinerBenedikt\AppData\Roaming\Mozilla\Firefox\Profiles\idkj7tmn.default-1386506584632\prefs.js ]
-\\ Google Chrome v
[ Datei : C:\Users\WasensteinerBenedikt\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [12504 octets] - [08/12/2013 17:19:43]
AdwCleaner[R1].txt - [1604 octets] - [09/12/2013 06:13:58]
AdwCleaner[R2].txt - [1664 octets] - [09/12/2013 06:16:28]
AdwCleaner[R3].txt - [4010 octets] - [31/01/2014 13:47:53]
AdwCleaner[R4].txt - [1389 octets] - [02/02/2014 09:36:27]
AdwCleaner[R5].txt - [1503 octets] - [05/02/2014 10:37:59]
AdwCleaner[S0].txt - [12008 octets] - [08/12/2013 17:20:51]
AdwCleaner[S1].txt - [1725 octets] - [09/12/2013 06:17:39]
AdwCleaner[S2].txt - [3914 octets] - [31/01/2014 13:49:22]
AdwCleaner[S3].txt - [1450 octets] - [02/02/2014 09:38:14]
AdwCleaner[S4].txt - [1424 octets] - [05/02/2014 10:42:05]
########## EOF - C:\AdwCleaner\AdwCleaner[S4].txt - [1484 octets] ##########
--- --- ---JRT Logfile:
Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.1 (02.04.2014:1)
OS: Windows 7 Home Premium x64
Ran by WasensteinerBenedikt on 05.02.2014 at 10:46:43,31
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader"
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.02.2014 at 10:55:07,08
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--- --- ---
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2014
Ran by WasensteinerBenedikt (administrator) on WASENSTEINERBEN on 05-02-2014 10:56:17
Running from D:\
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) F:\avast\AvastSvc.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
( ) C:\Windows\System32\lxbccoms.exe
( ) C:\Windows\System32\lxbvcoms.exe
(Malwarebytes Corporation) F:\Malwarebytes' Anti-Malware\mbamscheduler.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEPSON Connect\mepService.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEPSON Connect\mep.exe
(TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(AVAST Software) F:\avast\AvastUI.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(The Beamrise Authors) C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Mozilla Corporation) F:\mf\firefox.exe
(Mozilla Corporation) F:\mf\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_12_0_0_43.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [AvastUI.exe] - F:\avast\AvastUI.exe [3764024 2013-12-27] (AVAST Software)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKU\.DEFAULT\...\RunOnce: [SPReview] - C:\Windows\System32\SPReview\SPReview.exe [301568 2013-05-20] (Microsoft Corporation)
HKU\S-1-5-21-1772688737-64827690-100943929-1000\...\Run: [Beamrise] - C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise\Application\beamrise.exe [1569600 2014-01-16] (The Beamrise Authors)
HKU\S-1-5-21-1772688737-64827690-100943929-1000\...\MountPoints2: L - L:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1772688737-64827690-100943929-1000\...\MountPoints2: {9c2f085b-e595-11df-b844-806e6f6e6963} - J:\setup.exe
IFEO\htcsyncmanager.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IFEO\iastorui.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IFEO\ncc.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IFEO\nerostartsmart.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe"
IFEO\wordview.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2013\TUAutoReactivator64.exe"
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.nationzoom.com/web/?type=ds&ts=1386357019&from=tugs&uid=WDCXWD3200BEVT-22A23T0_WD-WXH1A60W1794W1794&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.nationzoom.com/?type=hp&ts=1386357019&from=tugs&uid=WDCXWD3200BEVT-22A23T0_WD-WXH1A60W1794W1794
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.nationzoom.com/?type=hp&ts=1386357019&from=tugs&uid=WDCXWD3200BEVT-22A23T0_WD-WXH1A60W1794W1794
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.nationzoom.com/web/?type=ds&ts=1386357019&from=tugs&uid=WDCXWD3200BEVT-22A23T0_WD-WXH1A60W1794W1794&q={searchTerms}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
BHO: Plus-HD-2.6 - {11111111-1111-1111-1111-110311341140} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - F:\avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - F:\avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - F:\avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - F:\avast\aswWebRepIE.dll (AVAST Software)
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\WasensteinerBenedikt\AppData\Roaming\Mozilla\Firefox\Profiles\idkj7tmn.default-1386506584632
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_43.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.1 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\WasensteinerBenedikt\AppData\Roaming\Mozilla\Firefox\Profiles\idkj7tmn.default-1386506584632\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-02]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - F:\avast\WebRep\FF
FF Extension: avast! Online Security - F:\avast\WebRep\FF [2013-12-27]
FF HKCU\...\Firefox\Extensions: [lyrix@lyrixeeker.co] - C:\Program Files (x86)\LyriXeeker\128.xpi
FF StartMenuInternet: FIREFOX.EXE - F:\mf\firefox.exe
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [epojlgbehpaeekopencdagbdamnkppci] - C:\Program Files (x86)\LyriXeeker\128.crx []
==================== Services (Whitelisted) =================
R2 avast! Antivirus; F:\avast\AvastSvc.exe [50344 2013-12-27] (AVAST Software)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
S4 HTCMonitorService; F:\htc\HSMServiceEntry.exe [87368 2013-11-10] (Nero AG)
R2 lxbc_device; C:\Windows\system32\lxbccoms.exe [566704 2007-03-16] ( )
R2 lxbc_device; C:\Windows\SysWOW64\lxbccoms.exe [537520 2007-03-16] ( )
R2 lxbv_device; C:\Windows\system32\lxbvcoms.exe [566704 2007-04-25] ( )
R2 lxbv_device; C:\Windows\SysWOW64\lxbvcoms.exe [537520 2007-04-25] ( )
R2 MBAMScheduler; F:\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; F:\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 MyEPSON Connect Service; C:\Program Files (x86)\EPSON\MyEPSON Connect\mepService.exe [703616 2012-10-01] (SEIKO EPSON CORPORATION)
S4 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesService64.exe [2412344 2014-01-28] (TuneUp Software)
S4 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect\Ath_WlanAgent.exe [57344 2011-08-10] (Atheros)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2013-12-27] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-12-27] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-12-27] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1034464 2013-12-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [422216 2013-12-27] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [79672 2013-12-27] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2013-12-27] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 SjtWinIo; C:\Windows\System32\DRIVERS\SjtWinIo.sys [9216 2010-11-02] (SpeedJet Technology INC.)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2013\TuneUpUtilitiesDriver64.sys [11880 2012-11-16] (TuneUp Software)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13784 2009-11-02] ()
S2 BstHdDrv; \??\C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [X]
S3 BTATH_BUS; system32\DRIVERS\btath_bus.sys [X]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-02-05 10:55 - 2014-02-05 10:55 - 00000923 _____ () C:\Users\WasensteinerBenedikt\Desktop\JRT.txt
2014-02-05 10:25 - 2014-02-05 10:25 - 00000627 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-05 10:25 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-02-02 17:26 - 2014-02-05 10:33 - 00008368 _____ () C:\Windows\PFRO.log
2014-02-02 13:28 - 2014-02-02 13:29 - 00001289 _____ () C:\Users\Public\Desktop\YTD Video Downloader.lnk
2014-02-02 13:28 - 2014-02-02 13:28 - 00000000 ____D () C:\Program Files (x86)\GreenTree Applications
2014-02-02 09:39 - 2014-02-05 10:42 - 00000504 _____ () C:\Windows\setupact.log
2014-02-02 09:39 - 2014-02-02 09:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-01 10:55 - 2014-02-01 10:56 - 00063946 _____ () C:\Users\WasensteinerBenedikt\Documents\cc_20140201_105556.reg
2014-02-01 10:51 - 2014-02-01 10:51 - 00002802 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-02-01 10:51 - 2014-02-01 10:51 - 00000826 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-02-01 10:51 - 2014-02-01 10:51 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-30 20:16 - 2014-01-30 20:17 - 00000000 ____D () C:\Program Files (x86)\Mobogenie
2014-01-30 20:15 - 2014-01-30 20:15 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\BeamriseUninstall
2014-01-30 20:15 - 2014-01-30 20:15 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise
2014-01-28 10:40 - 2014-01-28 10:39 - 00016455 _____ () C:\Users\WasensteinerBenedikt\Documents\rahmen zwischen ofen und küche dg.skb
2014-01-28 10:39 - 2014-01-28 10:40 - 00016455 _____ () C:\Users\WasensteinerBenedikt\Documents\rahmen zwischen ofen und küche dg.skp
2014-01-26 16:23 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-26 16:23 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-26 16:23 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-26 16:23 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-26 16:23 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-26 16:23 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-26 16:23 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-26 16:23 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-26 16:02 - 2014-01-26 16:02 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Roaming\Epson
2014-01-26 14:16 - 2014-02-05 10:22 - 00000911 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Update {8508887D-9AA1-48A6-A639-AF822DA5B5F4}.job
2014-01-26 14:16 - 2014-02-05 10:22 - 00000725 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Invitation {8508887D-9AA1-48A6-A639-AF822DA5B5F4}.job
2014-01-26 14:16 - 2014-01-26 14:16 - 00003978 _____ () C:\Windows\System32\Tasks\EPSON XP-215 217 Series Update {8508887D-9AA1-48A6-A639-AF822DA5B5F4}
2014-01-26 14:16 - 2014-01-26 14:16 - 00003792 _____ () C:\Windows\System32\Tasks\EPSON XP-215 217 Series Invitation {8508887D-9AA1-48A6-A639-AF822DA5B5F4}
2014-01-26 14:16 - 2014-01-26 14:16 - 00000000 ____D () C:\Program Files\Common Files\EPSON
2014-01-26 14:11 - 2014-01-26 14:11 - 00000000 ____D () C:\Program Files\EpsonNet
2014-01-26 14:11 - 2012-11-12 20:41 - 00535552 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\ensppui.dll
2014-01-26 14:11 - 2012-11-12 20:41 - 00535552 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\enppui.dll
2014-01-26 14:11 - 2012-11-12 15:15 - 00558592 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\ensppmon.dll
2014-01-26 14:11 - 2012-11-12 15:15 - 00558592 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\enppmon.dll
2014-01-26 14:11 - 2012-10-22 17:19 - 00219648 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\enspres.dll
2014-01-26 14:11 - 2012-10-22 17:19 - 00219648 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\enpres.dll
2014-01-26 14:10 - 2014-01-26 14:10 - 00000930 _____ () C:\Users\Public\Desktop\EPSON Scan.lnk
2014-01-26 14:10 - 2012-07-24 00:00 - 00466432 _____ (Seiko Epson Corporation) C:\Windows\system32\esxw2ud.dll
2014-01-26 14:10 - 2012-05-17 00:00 - 00144560 _____ (Seiko Epson Corporation) C:\Windows\system32\escsvc64.exe
2014-01-26 14:08 - 2013-10-22 04:04 - 00179712 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_ILMBLGE.DLL
2014-01-26 14:08 - 2011-03-15 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_ID4BLGE.DLL
2014-01-26 14:08 - 2007-04-10 01:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\Windows\system32\E_GCINST.DLL
2014-01-26 08:53 - 2014-01-26 14:23 - 00000000 ____D () C:\Program Files (x86)\EPSON Software
2014-01-26 08:53 - 2014-01-26 14:23 - 00000000 ____D () C:\Program Files (x86)\epson
2014-01-26 08:51 - 2014-01-26 14:18 - 00000000 ____D () C:\ProgramData\Epson
2014-01-13 17:38 - 2014-01-13 17:38 - 00000000 ____D () C:\Users\WasensteinerBenedikt\Desktop\Neuer Ordner
2014-01-09 18:44 - 2014-01-09 18:44 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-09 18:43 - 2014-01-09 18:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-09 18:43 - 2014-01-09 18:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
==================== One Month Modified Files and Folders =======
2014-02-05 10:56 - 2013-12-08 16:59 - 00000000 ____D () C:\FRST
2014-02-05 10:55 - 2014-02-05 10:55 - 00000923 _____ () C:\Users\WasensteinerBenedikt\Desktop\JRT.txt
2014-02-05 10:43 - 2014-01-02 21:08 - 00000442 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-02-05 10:43 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-05 10:42 - 2014-02-02 09:39 - 00000504 _____ () C:\Windows\setupact.log
2014-02-05 10:42 - 2013-12-08 17:19 - 00000000 ____D () C:\AdwCleaner
2014-02-05 10:42 - 2010-11-01 09:57 - 02054664 _____ () C:\Windows\WindowsUpdate.log
2014-02-05 10:42 - 2009-07-14 05:45 - 00021504 _____ () C:\Windows\system32\umstartup000.etl
2014-02-05 10:42 - 2009-07-14 05:45 - 00013904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-02-05 10:42 - 2009-07-14 05:45 - 00013904 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-02-05 10:42 - 2009-07-14 05:45 - 00012288 _____ () C:\Windows\system32\umstartup.etl
2014-02-05 10:33 - 2014-02-02 17:26 - 00008368 _____ () C:\Windows\PFRO.log
2014-02-05 10:32 - 2013-12-27 18:26 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\genienext
2014-02-05 10:25 - 2014-02-05 10:25 - 00000627 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-02-05 10:22 - 2014-01-26 14:16 - 00000911 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Update {8508887D-9AA1-48A6-A639-AF822DA5B5F4}.job
2014-02-05 10:22 - 2014-01-26 14:16 - 00000725 _____ () C:\Windows\Tasks\EPSON XP-215 217 Series Invitation {8508887D-9AA1-48A6-A639-AF822DA5B5F4}.job
2014-02-05 10:22 - 2013-09-10 06:23 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-04 17:12 - 2009-07-14 18:58 - 02079016 _____ () C:\Windows\system32\perfh007.dat
2014-02-04 17:12 - 2009-07-14 18:58 - 00591120 _____ () C:\Windows\system32\perfc007.dat
2014-02-04 17:12 - 2009-07-14 06:13 - 00006428 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-04 07:20 - 2013-12-27 07:37 - 00004124 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-02-02 14:36 - 2013-03-24 18:40 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Roaming\vlc
2014-02-02 14:08 - 2010-11-01 10:21 - 00000000 ___RD () C:\Users\WasensteinerBenedikt\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-02-02 13:29 - 2014-02-02 13:28 - 00001289 _____ () C:\Users\Public\Desktop\YTD Video Downloader.lnk
2014-02-02 13:28 - 2014-02-02 13:28 - 00000000 ____D () C:\Program Files (x86)\GreenTree Applications
2014-02-02 12:56 - 2010-11-30 11:45 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\CrashDumps
2014-02-02 09:39 - 2014-02-02 09:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-01 10:56 - 2014-02-01 10:55 - 00063946 _____ () C:\Users\WasensteinerBenedikt\Documents\cc_20140201_105556.reg
2014-02-01 10:52 - 2010-11-24 09:51 - 00000000 ____D () C:\Windows\Minidump
2014-02-01 10:52 - 2010-11-01 09:51 - 00000000 ____D () C:\Windows\Panther
2014-02-01 10:51 - 2014-02-01 10:51 - 00002802 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-02-01 10:51 - 2014-02-01 10:51 - 00000826 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-02-01 10:51 - 2014-02-01 10:51 - 00000000 ____D () C:\Program Files\CCleaner
2014-01-31 09:17 - 2013-09-10 06:23 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-01-31 09:17 - 2013-03-21 21:31 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-31 09:17 - 2013-03-21 21:31 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-30 20:17 - 2014-01-30 20:16 - 00000000 ____D () C:\Program Files (x86)\Mobogenie
2014-01-30 20:17 - 2013-12-08 16:53 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\Mobogenie
2014-01-30 20:16 - 2013-12-08 16:53 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\cache
2014-01-30 20:15 - 2014-01-30 20:15 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\BeamriseUninstall
2014-01-30 20:15 - 2014-01-30 20:15 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\Beamrise
2014-01-30 13:12 - 2013-06-30 11:16 - 00000000 ____D () C:\Program Files (x86)\TuneUp Utilities 2013
2014-01-28 10:40 - 2014-01-28 10:39 - 00016455 _____ () C:\Users\WasensteinerBenedikt\Documents\rahmen zwischen ofen und küche dg.skp
2014-01-28 10:39 - 2014-01-28 10:40 - 00016455 _____ () C:\Users\WasensteinerBenedikt\Documents\rahmen zwischen ofen und küche dg.skb
2014-01-28 09:35 - 2013-10-19 18:55 - 00038200 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll
2014-01-28 09:35 - 2013-10-19 18:55 - 00030520 _____ (TuneUp Software) C:\Windows\SysWOW64\uxtuneup.dll
2014-01-28 09:35 - 2013-06-30 11:17 - 00035640 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2014-01-28 09:35 - 2013-06-30 11:17 - 00026936 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2014-01-28 09:35 - 2013-06-30 11:17 - 00022328 _____ (TuneUp Software) C:\Windows\SysWOW64\authuitu.dll
2014-01-27 09:06 - 2009-07-14 05:45 - 00419760 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-27 09:00 - 2013-09-02 10:08 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-27 08:57 - 2010-11-01 19:51 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-26 16:06 - 2010-11-04 09:51 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\Adobe
2014-01-26 16:02 - 2014-01-26 16:02 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Roaming\Epson
2014-01-26 14:50 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\NDF
2014-01-26 14:23 - 2014-01-26 08:53 - 00000000 ____D () C:\Program Files (x86)\EPSON Software
2014-01-26 14:23 - 2014-01-26 08:53 - 00000000 ____D () C:\Program Files (x86)\epson
2014-01-26 14:23 - 2010-11-01 19:02 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-01-26 14:18 - 2014-01-26 08:51 - 00000000 ____D () C:\ProgramData\Epson
2014-01-26 14:16 - 2014-01-26 14:16 - 00003978 _____ () C:\Windows\System32\Tasks\EPSON XP-215 217 Series Update {8508887D-9AA1-48A6-A639-AF822DA5B5F4}
2014-01-26 14:16 - 2014-01-26 14:16 - 00003792 _____ () C:\Windows\System32\Tasks\EPSON XP-215 217 Series Invitation {8508887D-9AA1-48A6-A639-AF822DA5B5F4}
2014-01-26 14:16 - 2014-01-26 14:16 - 00000000 ____D () C:\Program Files\Common Files\EPSON
2014-01-26 14:11 - 2014-01-26 14:11 - 00000000 ____D () C:\Program Files\EpsonNet
2014-01-26 14:10 - 2014-01-26 14:10 - 00000930 _____ () C:\Users\Public\Desktop\EPSON Scan.lnk
2014-01-26 14:07 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\th-TH
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sl-SI
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\sk-SK
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\ro-RO
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\lv-LV
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\lt-LT
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\hr-HR
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\he-IL
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\et-EE
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\bg-BG
2014-01-26 13:58 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\system32\ar-SA
2014-01-26 13:57 - 2010-11-01 21:12 - 00006656 _____ () C:\Windows\system32\bcmwlrc.dll
2014-01-26 13:27 - 2010-11-01 19:03 - 00000000 ____D () C:\Program Files (x86)\Cisco
2014-01-26 09:11 - 2010-11-01 10:20 - 00000000 ____D () C:\Users\WasensteinerBenedikt
2014-01-26 09:10 - 2010-11-16 10:46 - 00000000 ___RD () C:\Users\WasensteinerBenedikt\Desktop\Programme
2014-01-26 09:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\security
2014-01-26 09:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\registration
2014-01-26 09:10 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\AppCompat
2014-01-26 09:09 - 2010-11-09 10:20 - 00000000 ____D () C:\Program Files (x86)\Java
2014-01-26 09:09 - 2010-11-01 19:51 - 00000000 ____D () C:\Users\WasensteinerBenedikt\AppData\Local\Mozilla
2014-01-13 17:38 - 2014-01-13 17:38 - 00000000 ____D () C:\Users\WasensteinerBenedikt\Desktop\Neuer Ordner
2014-01-12 18:10 - 2013-11-03 07:37 - 00000000 ____D () C:\Users\WasensteinerBenedikt\Desktop\bilder
2014-01-11 16:19 - 2010-11-09 15:27 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler
2014-01-09 18:44 - 2014-01-09 18:44 - 00000000 ____D () C:\ProgramData\Oracle
2014-01-09 18:43 - 2014-01-09 18:43 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-09 18:43 - 2014-01-09 18:43 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-09 18:43 - 2010-11-09 10:21 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-09 18:43 - 2010-11-09 10:21 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-08 19:57 - 2013-12-27 18:22 - 00000000 ____D () C:\Program Files (x86)\DriverToolkit
2014-01-06 19:57 - 2013-12-26 20:15 - 00000000 ____D () C:\Program Files (x86)\Qualcomm Atheros Fast Reconnect
2014-01-06 19:25 - 2010-11-01 19:19 - 00000000 ____D () C:\Program Files (x86)\Intel
Some content of TEMP:
====================
C:\Users\WasensteinerBenedikt\AppData\Local\Temp\BackupSetup.exe
C:\Users\WasensteinerBenedikt\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-30 19:04
==================== End Of Log ============================
--- --- ---