| nannynata | 20.04.2014 11:29 | Danke!
Hier die vier Dateien: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 20.04.2014 10:16:41, SYSTEM, WIN7-THINK, Protection, Malware Protection, Starting,
Protection, 20.04.2014 10:16:41, SYSTEM, WIN7-THINK, Protection, Malware Protection, Started,
Protection, 20.04.2014 10:16:41, SYSTEM, WIN7-THINK, Protection, Malicious Website Protection, Starting,
Protection, 20.04.2014 10:16:53, SYSTEM, WIN7-THINK, Protection, Malicious Website Protection, Started,
Update, 20.04.2014 10:16:54, SYSTEM, WIN7-THINK, Manual, Rootkit Database, 2014.2.20.1, 2014.3.27.1,
Update, 20.04.2014 10:17:02, SYSTEM, WIN7-THINK, Manual, Malware Database, 2014.3.4.9, 2014.4.20.3,
Protection, 20.04.2014 10:17:04, SYSTEM, WIN7-THINK, Protection, Refresh, Starting,
Protection, 20.04.2014 10:17:04, SYSTEM, WIN7-THINK, Protection, Malicious Website Protection, Stopping,
Protection, 20.04.2014 10:17:04, SYSTEM, WIN7-THINK, Protection, Malicious Website Protection, Stopped,
Protection, 20.04.2014 10:17:09, SYSTEM, WIN7-THINK, Protection, Refresh, Success,
Protection, 20.04.2014 10:17:09, SYSTEM, WIN7-THINK, Protection, Malicious Website Protection, Starting,
Protection, 20.04.2014 10:17:09, SYSTEM, WIN7-THINK, Protection, Malicious Website Protection, Started,
Detection, 20.04.2014 10:39:54, SYSTEM, WIN7-THINK, Protection, Malware Protection, File, PUP.Optional.SmartBar.A, C:\Users\WIN7\AppData\Local\Smartbar\Application\Lrcnta.exe, Quarantine, [831093990e6d36005095ef6fa45e9769]
Detection, 20.04.2014 10:57:01, SYSTEM, WIN7-THINK, Protection, Malware Protection, File, PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll, Quarantine, [276ce6467efd56e0034f2b3bd131db25]
Detection, 20.04.2014 10:57:01, SYSTEM, WIN7-THINK, Protection, Malware Protection, File, PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll, Quarantine, [098a89a35d1edd59c38f4a1c31d16c94]
Protection, 20.04.2014 10:57:01, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll,
Protection, 20.04.2014 10:57:01, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll,
Error, 20.04.2014 10:57:01, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll,
Error, 20.04.2014 10:57:01, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll,
Detection, 20.04.2014 11:09:54, SYSTEM, WIN7-THINK, Protection, Malware Protection, File, PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll, Quarantine, [276ce6467efd56e0034f2b3bd131db25]
Detection, 20.04.2014 11:09:54, SYSTEM, WIN7-THINK, Protection, Malware Protection, File, PUP.Optional.SettingsManager.A, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll, Quarantine, [098a89a35d1edd59c38f4a1c31d16c94]
Protection, 20.04.2014 11:09:54, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll,
Error, 20.04.2014 11:09:54, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\sysapcrt.dll,
Protection, 20.04.2014 11:09:55, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll,
Error, 20.04.2014 11:09:55, SYSTEM, WIN7-THINK, Protection, DeleteFile, 5, Failed, C:\Program Files (x86)\Settings Manager\systemk\x64\sysapcrt.dll,
(end) Code:
# AdwCleaner v3.100 - Bericht erstellt am 20/04/2014 um 11:18:26
# Aktualisiert 20/04/2014 von Xplode
# Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits)
# Benutzername : WIN7 - WIN7-THINK
# Gestartet von : C:\Users\WIN7\Downloads\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : DefaultTabUpdate
Dienst Gelöscht : IePluginService
Dienst Gelöscht : LPTSystemUpdater
Dienst Gelöscht : MovieMode
[#] Dienst Gelöscht : Re-markit
[#] Dienst Gelöscht : SystemkService
Dienst Gelöscht : TelevisionFanaticService
Dienst Gelöscht : wStLibG64
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Babylon
Ordner Gelöscht : C:\ProgramData\BitGuard
Ordner Gelöscht : C:\ProgramData\Browser Manager
Ordner Gelöscht : C:\ProgramData\BrowserProtect
Ordner Gelöscht : C:\ProgramData\IePluginService
Ordner Gelöscht : C:\ProgramData\MovieMode
Ordner Gelöscht : C:\ProgramData\Package Cache
Ordner Gelöscht : C:\ProgramData\ParetoLogic
Ordner Gelöscht : C:\ProgramData\Registry Helper
[!] Ordner Gelöscht : C:\ProgramData\systemk
Ordner Gelöscht : C:\ProgramData\wincert
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files (x86)\LPT
Ordner Gelöscht : C:\Program Files (x86)\Re-markit Corp
[!] Ordner Gelöscht : C:\Program Files (x86)\Settings Manager
Ordner Gelöscht : C:\Program Files (x86)\TelevisionFanatic
Ordner Gelöscht : C:\Users\WIN7\AppData\Local\MovieMode
Ordner Gelöscht : C:\Users\WIN7\AppData\Local\SearchProtect
Ordner Gelöscht : C:\Users\WIN7\AppData\Local\Smartbar
Ordner Gelöscht : C:\Users\WIN7\AppData\Local\TelevisionFanatic
Ordner Gelöscht : C:\Users\WIN7\AppData\Local\Temp\Smartbar
Ordner Gelöscht : C:\Users\WIN7\AppData\LocalLow\Smartbar
Ordner Gelöscht : C:\Users\WIN7\AppData\LocalLow\TelevisionFanatic
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\Activeris
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\Babylon
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\DriverCure
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\DVDVideoSoft
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\ParetoLogic
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\PerformerSoft
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\SupTab
Ordner Gelöscht : C:\Users\WIN7\AppData\Roaming\Systweak
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\WIN7\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\WIN7\AppData\Roaming\Mozilla\Firefox\Profiles\g5umr6n8.default\defaulttab.config
Datei Gelöscht : C:\Users\WIN7\AppData\Roaming\Mozilla\Firefox\Profiles\g5umr6n8.default\invalidprefs.js
Datei Gelöscht : C:\Users\WIN7\AppData\Roaming\Mozilla\Firefox\Profiles\g5umr6n8.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\LaunchApp
Datei Gelöscht : C:\Windows\Tasks\MySearchDial.job
Datei Gelöscht : C:\Windows\System32\Tasks\MySearchDial
***** [ Verknüpfungen ] *****
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Finale NotePad 2008\User Manual.lnk
Verknüpfung Desinfiziert : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Finale NotePad 2008\What's New.lnk
Verknüpfung Desinfiziert : C:\Users\WIN7\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [64ffxtbr@TelevisionFanatic.com]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\*\shell\filescout
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.bandobjectattribute
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.dockingpanel
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbar
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.iesmartbarbandobject
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbardisplaystate
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\iesmartbar.smartbarmenuform
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\speedupmypc
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\smartbar_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\VideoPerformerSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsemngr.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsermngr.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bundlesweetimsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cltmngsvc.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta babylon.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta tb.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\delta2.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltainstaller.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltasetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deltatb_2501-c733154b.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iminentsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sweetimsetup.exe
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\tbdelta.exetoolbar783881609.exe
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [Registry Helper]
Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x64]
Wert Gelöscht : HKLM\SYSTEM\ControlSet001\Control\Session Manager\AppCertDlls [x86]
Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x64]
Wert Gelöscht : HKLM\SYSTEM\ControlSet002\Control\Session Manager\AppCertDlls [x86]
Schlüssel Gelöscht : HKLM\SOFTWARE\d4888bb26db949
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{CBEF8724-D080-4737-88DA-111EEC6651AA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{006EE092-9658-4FD6-BD8E-A21A348E59F5}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{56561B2A-FB5D-363A-9631-4C03D6054209}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{A717364F-69F3-3A24-ADD5-3901A57F880E}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB08265-B35D-30B2-A6AF-6986CA957358}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CD92622E-49B9-33B7-98D1-EC51049457D7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{E041E037-FA4B-364A-B440-7A1051EA0301}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\APN PIP
Schlüssel Gelöscht : HKCU\Software\filescout
Schlüssel Gelöscht : HKCU\Software\installedbrowserextensions
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\ParetoLogic
Schlüssel Gelöscht : HKCU\Software\performersoft llc
Schlüssel Gelöscht : HKCU\Software\SmartBar
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\TelevisionFanatic
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\DynConIE
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\TelevisionFanatic
Schlüssel Gelöscht : HKLM\Software\Babylon
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\IePlugin
Schlüssel Gelöscht : HKLM\Software\installedbrowserextensions
Schlüssel Gelöscht : HKLM\Software\ParetoLogic
Schlüssel Gelöscht : HKLM\Software\PIP
Schlüssel Gelöscht : HKLM\Software\Registry Helper
Schlüssel Gelöscht : HKLM\Software\supTab
Schlüssel Gelöscht : HKLM\Software\supWPM
Schlüssel Gelöscht : HKLM\Software\systweak
Schlüssel Gelöscht : HKLM\Software\TelevisionFanatic
Schlüssel Gelöscht : HKLM\Software\Uniblue
Schlüssel Gelöscht : HKLM\Software\Wpm
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\installedbrowserextensions
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
Einstellung Wiederhergestellt : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\WIN7\AppData\Roaming\Mozilla\Firefox\Profiles\g5umr6n8.default\prefs.js ]
Zeile gelöscht : user_pref("browser.search.defaultenginename", "Mysearchdial");
Zeile gelöscht : user_pref("browser.search.order.1", "Mysearchdial");
Zeile gelöscht : user_pref("browser.search.selectedEngine", "Mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.instlRef", "140305_d");
Zeile gelöscht : user_pref("extensions.mysearchdial.lastB", "hxxp://start.mysearchdial.com/?f=1&a=dsites03_14_16_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyCyCtD0DtA0CyCyC0A0EzztN0D0Tzu0SzztAyCtN1L2XzutBtFtCzztFtBtFzztN1L1CzutC[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.lastVrsnTs", "1.8.29.013:36:54");
Zeile gelöscht : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=dsites03_14_16_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyCyCtD0DtA0CyCyC0A0EzztN0D0Tzu0SzztAyCtN1L2XzutBtFtCzztFtBtFzztN1L1C[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"95\",\"lastVrsn\":\"95\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
Zeile gelöscht : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.sg", "none");
Zeile gelöscht : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=dsites03_14_16_ff&cd=2XzuyEtN2Y1L1QzutDtDtBtCzzyCyCtD0DtA0CyCyC0A0EzztN0D0Tzu0SzztAyCtN1L2XzutBtFtCzztFtBtFzztN1L[...]
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsn", "1.8.29.0");
Zeile gelöscht : user_pref("extensions.mysearchdial.vrsni", "1.8.29.0");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.newTab", false);
Zeile gelöscht : user_pref("extensions.mysearchdial_i.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.mysearchdial_i.vrsnTs", "1.8.29.013:36:54");
*************************
AdwCleaner[R0].txt - [24834 octets] - [20/04/2014 11:17:22]
AdwCleaner[S0].txt - [23046 octets] - [20/04/2014 11:18:26]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [23107 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Professional x64
Ran by WIN7 on 20.04.2014 at 12:00:24,88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-686968082-478460626-418877182-1000\Software\sweetim
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\default tab
~~~ Files
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\apn"
Successfully deleted: [Folder] "C:\Users\WIN7\appdata\locallow\datamngr"
~~~ FireFox
Emptied folder: C:\Users\WIN7\AppData\Roaming\mozilla\firefox\profiles\g5umr6n8.default\minidumps [147 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 20.04.2014 at 12:08:46,00
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ und die neu erstellte FRST:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-04-2014 01
Ran by WIN7 (administrator) on WIN7-THINK on 20-04-2014 12:12:42
Running from C:\Users\WIN7\Downloads
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Lenovo) C:\Windows\system32\ibmpmsvc.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo.) C:\Windows\System32\TpShocks.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Jumping Bytes) C:\Program Files (x86)\PureSync\PureSyncTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
() C:\Users\WIN7\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
(Avanquest Software ) C:\Program Files (x86)\Digital Line Detect\DLG.exe
(Nero AG) C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Program Files (x86)\HTC\HTC Sync Manager\HTC Sync\adb.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(SMART Technologies) C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Broadcom Corporation.) C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe
(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\LMS.exe
(Lenovo Group Limited) c:\Program Files (x86)\Lenovo\System Update\SUService.exe
(Lenovo Group Limited) C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe
(Intel Corporation) C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(RealNetworks, Inc.) C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1815848 2009-07-14] (Synaptics Incorporated)
HKLM\...\Run: [picon] => C:\Program Files (x86)\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe [358424 2009-08-04] (Intel Corporation)
HKLM\...\Run: [TpShocks] => C:\Windows\system32\TpShocks.exe [380704 2009-07-09] (Lenovo.)
HKLM\...\Run: [AcWin7Hlpr] => C:\Program Files (x86)\Lenovo\Access Connections\AcWin7Hlpr.exe showdeskband
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-25] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [118104 2014-04-01] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-686968082-478460626-418877182-1000\...\Run: [PureSync] => C:\Program Files (x86)\PureSync\PureSyncTray.exe [903712 2013-02-01] (Jumping Bytes)
HKU\S-1-5-21-686968082-478460626-418877182-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [720064 2013-04-22] (Microsoft Corporation)
HKU\S-1-5-21-686968082-478460626-418877182-1000\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\WIN7\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-686968082-478460626-418877182-1000\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [118104 2014-04-01] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-686968082-478460626-418877182-1000\...\MountPoints2: {64cf642f-73c4-11e3-b6ca-00218660d3c6} - D:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-686968082-478460626-418877182-1000\...\MountPoints2: {a104613f-73cc-11e3-b4bc-00218660d3c6} - D:\Setup.exe
HKU\S-1-5-21-686968082-478460626-418877182-1000\...\MountPoints2: {e6343ce2-6fd0-11e2-879a-806e6f6e6963} - Q:\LenovoQDrive.exe
IFEO\bpsvc.exe: [Debugger] tasklist.exe
IFEO\browsersafeguard.exe: [Debugger] tasklist.exe
IFEO\dprotectsvc.exe: [Debugger] tasklist.exe
IFEO\jumpflip: [Debugger] tasklist.exe
IFEO\protectedsearch.exe: [Debugger] tasklist.exe
IFEO\rjatydimofu.exe: [Debugger] tasklist.exe
IFEO\searchinstaller.exe: [Debugger] tasklist.exe
IFEO\searchprotection.exe: [Debugger] tasklist.exe
IFEO\searchprotector.exe: [Debugger] tasklist.exe
IFEO\searchsettings.exe: [Debugger] tasklist.exe
IFEO\searchsettings64.exe: [Debugger] tasklist.exe
IFEO\snapdo.exe: [Debugger] tasklist.exe
IFEO\stinst32.exe: [Debugger] tasklist.exe
IFEO\stinst64.exe: [Debugger] tasklist.exe
IFEO\umbrella.exe: [Debugger] tasklist.exe
IFEO\utiljumpflip.exe: [Debugger] tasklist.exe
IFEO\volaro: [Debugger] tasklist.exe
IFEO\vonteera: [Debugger] tasklist.exe
IFEO\websteroids.exe: [Debugger] tasklist.exe
IFEO\websteroidsservice.exe: [Debugger] tasklist.exe
HKLM\...\AppCertDlls: [x64] -> c:\program files (x86)\settings manager\systemk\x64\sysapcrt.dll
HKLM\...\AppCertDlls: [x86] -> c:\program files (x86)\settings manager\systemk\sysapcrt.dll
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
ProxyEnable: Internet Explorer proxy is enabled.
ProxyServer: http=127.0.0.1:13828
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = hxxp://www.default-search.net/search?sid=498&aid=103&itype=a&ver=12302&tm=310&src=ds&p={searchTerms}
SearchScopes: HKCU - {9BB47C17-9C68-4BB3-B188-DD9AF0FD2498} URL = hxxp://www.default-search.net/search?sid=498&aid=103&itype=a&ver=12302&tm=310&src=ds&p={searchTerms}
BHO: SMART Notebook Download Utility - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files (x86)\SMART Technologies\Education Software\Win64\NotebookPlugin.dll (SMART Technologies ULC.)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: SMART Notebook Download Utility - {67BCF957-85FC-4036-8DC4-D4D80E00A77B} - C:\Program Files (x86)\SMART Technologies\Education Software\Win32\NotebookPlugin.dll (SMART Technologies ULC.)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\WIN7\AppData\Roaming\Mozilla\Firefox\Profiles\g5umr6n8.default
FF Homepage: hxxp://www.google.de/
FF NetworkProxy: "type", 4
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_182.dll ()
FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @Musicnotes.com/Musicnotes Viewer - C:\Program Files\Musicnotes\npmusicn64.dll (Musicnotes, Inc.)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_182.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll No File
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @Musicnotes.com/Musicnotes Viewer - C:\Program Files (x86)\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF Plugin-x32: @real.com/nppl3260;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.2.32 - C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @Sibelius.com/Scorch Plugin - C:\Program Files (x86)\Musicnotes\npsibelius.dll ()
FF Plugin-x32: @TelevisionFanatic.com/Plugin - C:\Program Files (x86)\TelevisionFanatic\bar\1.bin\NP64Stub.dll No File
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\WIN7\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll (RealNetworks, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll (RealPlayer)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Settings Manager - C:\Users\WIN7\AppData\Roaming\Mozilla\Firefox\Profiles\g5umr6n8.default\Extensions\{2AE40B21-2432-2852-F891-21943FB49383} [2014-04-10]
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-05-30]
FF HKLM-x32\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ []
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-25] (Avira Operations GmbH & Co. KG)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [431960 2014-04-01] (Garmin Ltd or its subsidiaries)
R2 HTCMonitorService; C:\Program Files (x86)\HTC\HTC Sync Manager\HSMServiceEntry.exe [87368 2013-01-29] (Nero AG)
R2 LMS; C:\Program Files (x86)\Intel\AMT\LMS.exe [174616 2009-08-04] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-04-03] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [857912 2014-04-03] (Malwarebytes Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [167424 2012-12-07] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 SMARTHelperService; C:\Program Files (x86)\SMART Technologies\Education Software\SMARTHelperService.exe [582552 2012-10-24] (SMART Technologies)
R2 ThinkVantage Registry Monitor Service; C:\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe [1019904 2009-08-29] (Lenovo Group Limited)
S3 TVT Backup Service; C:\Program Files (x86)\Lenovo\Rescue and Recovery\rrservice.exe [1474560 2009-09-04] (Lenovo Group Limited)
R2 UNS; C:\Program Files (x86)\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2058776 2009-08-04] (Intel Corporation)
==================== Drivers (Whitelisted) ====================
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-02-25] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-04-03] (Malwarebytes Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [119512 2014-04-20] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63192 2014-04-03] (Malwarebytes Corporation)
S3 nokia_usb_modem_cdc_acm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_acm.sys [79872 2011-06-22] (Nokia)
S3 nokia_usb_modem_cdc_ecm; C:\Windows\System32\DRIVERS\nokia_usb_modem_cdc_ecm.sys [58880 2011-06-22] (Nokia)
S3 nokia_usb_modem_cpo; C:\Windows\System32\DRIVERS\nokia_usb_modem_cpo.sys [14336 2011-06-22] (Nokia)
S3 nokia_usb_modem_ecm_enum; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum.sys [56320 2011-06-22] (Nokia)
S3 nokia_usb_modem_ecm_enum_filter; C:\Windows\System32\DRIVERS\nokia_usb_modem_ecm_enum_filter.sys [56320 2011-06-22] (Nokia)
R3 SMARTMouseFilterx64; C:\Windows\System32\DRIVERS\SMARTMouseFilterx64.sys [16280 2012-10-24] (SMART Technologies)
R3 SMARTVHidMiniVistaAmd64; C:\Windows\System32\DRIVERS\SMARTVHidMiniVistaAmd64.sys [15256 2012-10-24] (SMART Technologies)
R3 SMARTVTabletPCx64; C:\Windows\System32\DRIVERS\SMARTVTabletPCx64.sys [24984 2012-10-24] (SMART Technologies ULC)
R1 TPPWRIF; C:\Windows\System32\drivers\Tppwr64v.sys [13104 2009-08-23] ()
R3 TVTI2C; C:\Windows\System32\DRIVERS\Tvti2c.sys [41536 2009-07-02] (Lenovo (United States) Inc.)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Corporation)
S3 PCDSRVC{184E4FA0-DE8C26D4-06000000}_0; \??\c:\progra~1\pc-doc~1\pcdsrvc_x64.pkms [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-20 12:08 - 2014-04-20 12:08 - 00001150 _____ () C:\Users\WIN7\Desktop\JRT.txt
2014-04-20 12:00 - 2014-04-20 12:00 - 00000000 ____D () C:\Windows\ERUNT
2014-04-20 11:57 - 2014-04-20 11:57 - 01016261 _____ (Thisisu) C:\Users\WIN7\Downloads\JRT.exe
2014-04-20 11:31 - 2014-04-20 11:31 - 00023404 _____ () C:\Users\WIN7\Desktop\AdwCleaner[S0].txt
2014-04-20 11:20 - 2014-04-20 11:20 - 00447438 _____ () C:\Windows\PFRO.log
2014-04-20 11:17 - 2014-04-20 11:18 - 00000000 ____D () C:\AdwCleaner
2014-04-20 11:16 - 2014-04-20 11:16 - 01308369 _____ () C:\Users\WIN7\Downloads\adwcleaner.exe
2014-04-20 11:11 - 2014-04-20 11:11 - 00003640 _____ () C:\Users\WIN7\Desktop\MBAM.txt
2014-04-20 10:16 - 2014-04-20 11:25 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-20 10:16 - 2014-04-20 10:16 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-20 10:16 - 2014-04-20 10:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-20 10:16 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-20 10:16 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-20 10:16 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-20 10:15 - 2014-04-20 10:15 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\WIN7\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-18 10:30 - 2014-04-18 10:30 - 00048378 _____ () C:\Users\WIN7\Downloads\Addition.txt
2014-04-18 10:29 - 2014-04-20 12:12 - 00020262 _____ () C:\Users\WIN7\Downloads\FRST.txt
2014-04-18 10:29 - 2014-04-20 12:12 - 00000000 ____D () C:\FRST
2014-04-18 10:28 - 2014-04-18 10:28 - 02158592 _____ (Farbar) C:\Users\WIN7\Downloads\FRST64.exe
2014-04-18 09:02 - 2014-04-18 09:46 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-18 09:02 - 2014-04-18 09:46 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-04-17 21:51 - 2014-04-17 21:51 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-17 21:30 - 2014-04-17 21:30 - 00000000 ____D () C:\Program Files\7-Zip
2014-04-17 20:45 - 2014-04-17 21:35 - 00003342 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-686968082-478460626-418877182-1000
2014-04-17 20:42 - 2014-04-20 11:21 - 00000448 _____ () C:\Windows\setupact.log
2014-04-17 20:42 - 2014-04-17 20:42 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-17 20:41 - 2014-04-17 20:41 - 00000000 ___RD () C:\Users\WIN7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-16 13:54 - 2014-04-16 13:54 - 00000000 ____D () C:\Program Files\CONEXANT
2014-04-16 13:11 - 2014-04-16 13:11 - 00000000 ____D () C:\Users\WIN7\AppData\Roaming\DriverFinder
2014-04-16 10:47 - 2014-04-16 10:47 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-04-16 08:27 - 2014-04-16 08:27 - 00007609 _____ () C:\Users\WIN7\AppData\Local\Resmon.ResmonCfg
2014-04-16 08:12 - 2014-04-16 08:12 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log
2014-04-16 08:12 - 2014-03-17 22:11 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-04-16 08:12 - 2014-03-17 22:02 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-04-16 08:12 - 2014-03-17 22:02 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-04-16 08:12 - 2014-03-17 22:02 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-04-16 07:58 - 2009-11-10 19:29 - 00035791 ____N () C:\Windows\TPUNHERW.CAT
2014-04-16 07:57 - 2009-10-05 18:56 - 01811968 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64TP17.dll
2014-04-16 07:57 - 2009-10-05 17:58 - 00649216 _____ (Conexant Systems Inc.) C:\Windows\system32\Drivers\CHDRT64.sys
2014-04-16 07:57 - 2009-08-16 20:19 - 00398848 _____ (Conexant Systems, Inc.) C:\Windows\system32\UCI64A42.dll
2014-04-15 23:29 - 2014-02-16 15:03 - 00000426 _____ () C:\AVScanner.ini
2014-04-15 23:22 - 2014-04-15 23:22 - 00000000 ____D () C:\Users\WIN7\AppData\Local\com
2014-04-15 23:18 - 2014-04-15 23:18 - 01097384 _____ (AnyProtect.com) C:\Users\WIN7\AppData\Local\nss615D.tmp
2014-04-12 07:16 - 2014-04-12 07:16 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Garmin
2014-04-12 07:16 - 2014-04-12 07:16 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Garmin
2014-04-12 07:15 - 2014-04-12 07:15 - 00001899 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-04-07 15:37 - 2014-04-07 15:37 - 00003122 _____ () C:\Windows\System32\Tasks\{037A3591-43CF-4C6E-8A81-1AE6759FCBFE}
2014-04-07 15:35 - 2014-04-07 15:35 - 01171848 _____ (AnyProtect.com) C:\Users\WIN7\AppData\Local\nsj6DE2.tmp
2014-04-07 15:33 - 2014-04-16 08:06 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-07 15:13 - 2014-04-20 12:13 - 00000280 _____ () C:\Windows\Tasks\FF Watcher {E22A9299-1125-4B6E-AAD5-9B059BCA1F85}.job
2014-04-07 15:13 - 2014-04-07 15:13 - 00003778 _____ () C:\Windows\System32\Tasks\DTReg
2014-04-07 15:13 - 2014-04-07 15:13 - 00003248 _____ () C:\Windows\System32\Tasks\FF Watcher {E22A9299-1125-4B6E-AAD5-9B059BCA1F85}
2014-04-07 15:13 - 2014-04-07 15:13 - 00000932 __RSH () C:\Users\WIN7\ntuser.pol
2014-04-04 03:02 - 2014-03-01 08:05 - 23133696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-04 03:02 - 2014-03-01 07:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-04 03:02 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-04 03:02 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-04 03:02 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-04 03:02 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-04 03:02 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-04 03:02 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-04 03:02 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-04 03:02 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-04 03:02 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-04 03:02 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-04 03:02 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-04 03:02 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-04 03:02 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-04 03:02 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-04 03:02 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-04 03:02 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-04 03:02 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-04 03:02 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-04 03:02 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-04 03:02 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-04 03:02 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-04 03:02 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-04 03:02 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-04 03:02 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-04 03:02 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-04 03:02 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-04 03:02 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-04 03:02 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-04 03:02 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-04 03:02 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-04 03:02 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-04 03:02 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-04 03:02 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-04 03:02 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-04 03:02 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-04 03:02 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-04 03:02 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-04 03:02 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-04 03:01 - 2014-04-04 03:00 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-04 03:00 - 2013-12-21 11:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-04 03:00 - 2013-12-21 10:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-03 17:34 - 2014-04-17 21:35 - 00003206 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-686968082-478460626-418877182-1000
2014-04-03 17:28 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2014-04-02 20:00 - 2014-04-02 20:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-04-02 20:00 - 2014-04-02 20:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-04-02 20:00 - 2014-04-02 20:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-04-02 20:00 - 2014-04-02 20:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-04-02 20:00 - 2014-04-02 20:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-04-02 20:00 - 2014-04-02 20:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-04-02 20:00 - 2014-04-02 20:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-04-02 16:43 - 2014-04-02 16:43 - 00000000 ____D () C:\Users\WIN7\AppData\Roaming\Avira
2014-04-02 16:42 - 2014-04-02 16:42 - 00002073 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-04-02 16:42 - 2014-04-02 16:42 - 00000000 ____D () C:\ProgramData\Avira
2014-04-02 16:42 - 2014-04-02 16:42 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-04-02 16:42 - 2014-02-25 11:41 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2014-04-02 16:42 - 2014-02-25 11:41 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-04-02 16:42 - 2014-02-25 11:41 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2014-04-02 16:28 - 2014-04-16 11:20 - 00003364 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-686968082-478460626-418877182-1000
2014-04-02 16:28 - 2014-04-16 11:20 - 00003228 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-686968082-478460626-418877182-1000
2014-03-21 10:51 - 2014-03-21 10:51 - 01161872 _____ () C:\Windows\SysWOW64\MovieMode.48CA2AEFA22D.dll
==================== One Month Modified Files and Folders =======
2014-04-20 12:13 - 2014-04-18 10:29 - 00020262 _____ () C:\Users\WIN7\Downloads\FRST.txt
2014-04-20 12:13 - 2014-04-07 15:13 - 00000280 _____ () C:\Windows\Tasks\FF Watcher {E22A9299-1125-4B6E-AAD5-9B059BCA1F85}.job
2014-04-20 12:12 - 2014-04-18 10:29 - 00000000 ____D () C:\FRST
2014-04-20 12:08 - 2014-04-20 12:08 - 00001150 _____ () C:\Users\WIN7\Desktop\JRT.txt
2014-04-20 12:00 - 2014-04-20 12:00 - 00000000 ____D () C:\Windows\ERUNT
2014-04-20 11:57 - 2014-04-20 11:57 - 01016261 _____ (Thisisu) C:\Users\WIN7\Downloads\JRT.exe
2014-04-20 11:57 - 2013-02-25 19:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-04-20 11:31 - 2014-04-20 11:31 - 00023404 _____ () C:\Users\WIN7\Desktop\AdwCleaner[S0].txt
2014-04-20 11:31 - 2009-07-14 06:45 - 00026208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-20 11:31 - 2009-07-14 06:45 - 00026208 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-20 11:28 - 2013-02-05 22:19 - 01094448 _____ () C:\Windows\WindowsUpdate.log
2014-04-20 11:25 - 2014-04-20 10:16 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-20 11:22 - 2013-06-27 19:21 - 00000000 ____D () C:\Users\WIN7\AppData\Local\HTC MediaHub
2014-04-20 11:21 - 2014-04-17 20:42 - 00000448 _____ () C:\Windows\setupact.log
2014-04-20 11:21 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-20 11:20 - 2014-04-20 11:20 - 00447438 _____ () C:\Windows\PFRO.log
2014-04-20 11:20 - 2009-07-14 09:45 - 00000000 ____D () C:\Windows\ShellNew
2014-04-20 11:18 - 2014-04-20 11:17 - 00000000 ____D () C:\AdwCleaner
2014-04-20 11:16 - 2014-04-20 11:16 - 01308369 _____ () C:\Users\WIN7\Downloads\adwcleaner.exe
2014-04-20 11:11 - 2014-04-20 11:11 - 00003640 _____ () C:\Users\WIN7\Desktop\MBAM.txt
2014-04-20 10:16 - 2014-04-20 10:16 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-20 10:16 - 2014-04-20 10:16 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-20 10:15 - 2014-04-20 10:15 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\WIN7\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-19 12:10 - 2013-02-05 23:01 - 00699340 _____ () C:\Windows\system32\perfh007.dat
2014-04-19 12:10 - 2013-02-05 23:01 - 00149448 _____ () C:\Windows\system32\perfc007.dat
2014-04-19 12:10 - 2009-07-14 07:13 - 01619272 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-18 10:30 - 2014-04-18 10:30 - 00048378 _____ () C:\Users\WIN7\Downloads\Addition.txt
2014-04-18 10:28 - 2014-04-18 10:28 - 02158592 _____ (Farbar) C:\Users\WIN7\Downloads\FRST64.exe
2014-04-18 09:48 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-18 09:46 - 2014-04-18 09:02 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-04-18 09:46 - 2014-04-18 09:02 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-04-18 09:23 - 2013-02-05 14:27 - 00000000 ____D () C:\Users\WIN7
2014-04-18 08:45 - 2013-02-25 17:27 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-17 21:58 - 2013-02-25 19:51 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-04-17 21:58 - 2013-02-25 19:51 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-17 21:58 - 2013-02-25 19:51 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-04-17 21:58 - 2013-02-11 22:38 - 00000000 ____D () C:\Users\WIN7\AppData\Local\Adobe
2014-04-17 21:51 - 2014-04-17 21:51 - 00001154 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-04-17 21:51 - 2014-03-19 19:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-17 21:35 - 2014-04-17 20:45 - 00003342 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-686968082-478460626-418877182-1000
2014-04-17 21:35 - 2014-04-03 17:34 - 00003206 _____ () C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-686968082-478460626-418877182-1000
2014-04-17 21:30 - 2014-04-17 21:30 - 00000000 ____D () C:\Program Files\7-Zip
2014-04-17 20:42 - 2014-04-17 20:42 - 00000000 _____ () C:\Windows\setuperr.log
2014-04-17 20:41 - 2014-04-17 20:41 - 00000000 ___RD () C:\Users\WIN7\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-04-17 18:34 - 2013-11-24 12:07 - 00000000 ____D () C:\Users\WIN7\Tracing
2014-04-17 18:21 - 2013-02-05 23:00 - 00000000 ____D () C:\Windows\SysWOW64\XPSViewer
2014-04-17 18:21 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\addins
2014-04-17 18:21 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-04-17 18:21 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files\MSBuild
2014-04-17 18:21 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\Reference Assemblies
2014-04-17 18:21 - 2009-07-14 07:32 - 00000000 ____D () C:\Program Files (x86)\MSBuild
2014-04-17 18:21 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Setup
2014-04-16 13:54 - 2014-04-16 13:54 - 00000000 ____D () C:\Program Files\CONEXANT
2014-04-16 13:11 - 2014-04-16 13:11 - 00000000 ____D () C:\Users\WIN7\AppData\Roaming\DriverFinder
2014-04-16 11:20 - 2014-04-02 16:28 - 00003364 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-686968082-478460626-418877182-1000
2014-04-16 11:20 - 2014-04-02 16:28 - 00003228 _____ () C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-686968082-478460626-418877182-1000
2014-04-16 10:47 - 2014-04-16 10:47 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\wStLibG64.sys
2014-04-16 08:45 - 2013-02-05 22:40 - 00000000 ____D () C:\Windows\System32\Tasks\TVT
2014-04-16 08:45 - 2013-02-05 22:39 - 00000000 ____D () C:\ProgramData\Lenovo
2014-04-16 08:27 - 2014-04-16 08:27 - 00007609 _____ () C:\Users\WIN7\AppData\Local\Resmon.ResmonCfg
2014-04-16 08:12 - 2014-04-16 08:12 - 00004253 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b13.log
2014-04-16 08:12 - 2013-10-26 15:54 - 00000000 ____D () C:\ProgramData\Oracle
2014-04-16 08:12 - 2013-02-12 13:41 - 00000000 ____D () C:\Program Files (x86)\Java
2014-04-16 08:06 - 2014-04-07 15:33 - 00000512 __RSH () C:\ProgramData\ntuser.pol
2014-04-15 23:28 - 2013-02-05 22:25 - 00000000 ____D () C:\Program Files\ThinkPad
2014-04-15 23:22 - 2014-04-15 23:22 - 00000000 ____D () C:\Users\WIN7\AppData\Local\com
2014-04-15 23:18 - 2014-04-15 23:18 - 01097384 _____ (AnyProtect.com) C:\Users\WIN7\AppData\Local\nss615D.tmp
2014-04-12 07:20 - 2013-03-23 21:44 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-04-12 07:18 - 2014-03-11 11:47 - 00000000 ____D () C:\Users\WIN7\AppData\Roaming\Garmin
2014-04-12 07:18 - 2013-09-01 12:29 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-12 07:16 - 2014-04-12 07:16 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Garmin
2014-04-12 07:16 - 2014-04-12 07:16 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Garmin
2014-04-12 07:15 - 2014-04-12 07:15 - 00001899 _____ () C:\Users\Public\Desktop\Garmin Express.lnk
2014-04-12 07:15 - 2014-03-10 20:35 - 00003554 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2014-04-12 07:15 - 2014-03-10 20:35 - 00000000 ____D () C:\ProgramData\Garmin
2014-04-12 07:15 - 2014-03-10 20:35 - 00000000 ____D () C:\Program Files (x86)\Garmin
2014-04-12 07:13 - 2013-02-12 11:42 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-11 15:17 - 2009-07-24 19:29 - 00000000 ____D () C:\Windows\Panther
2014-04-10 16:03 - 2013-03-26 12:49 - 00000000 ____D () C:\Users\WIN7\Documents\Fax
2014-04-09 06:43 - 2013-03-23 22:03 - 00000000 ____D () C:\Users\WIN7\AppData\Local\Deployment
2014-04-07 16:02 - 2013-05-01 10:23 - 00000000 ____D () C:\Users\WIN7\AppData\Roaming\Dropbox
2014-04-07 15:53 - 2013-04-01 19:55 - 00000000 ____D () C:\Users\WIN7\AppData\Roaming\Real
2014-04-07 15:37 - 2014-04-07 15:37 - 00003122 _____ () C:\Windows\System32\Tasks\{037A3591-43CF-4C6E-8A81-1AE6759FCBFE}
2014-04-07 15:35 - 2014-04-07 15:35 - 01171848 _____ (AnyProtect.com) C:\Users\WIN7\AppData\Local\nsj6DE2.tmp
2014-04-07 15:13 - 2014-04-07 15:13 - 00003778 _____ () C:\Windows\System32\Tasks\DTReg
2014-04-07 15:13 - 2014-04-07 15:13 - 00003248 _____ () C:\Windows\System32\Tasks\FF Watcher {E22A9299-1125-4B6E-AAD5-9B059BCA1F85}
2014-04-07 15:13 - 2014-04-07 15:13 - 00000932 __RSH () C:\Users\WIN7\ntuser.pol
2014-04-07 15:13 - 2009-07-14 05:20 - 00000000 ___HD () C:\Windows\system32\GroupPolicy
2014-04-07 15:13 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\GroupPolicy
2014-04-04 03:00 - 2014-04-04 03:01 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-04-03 09:51 - 2014-04-20 10:16 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-20 10:16 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-20 10:16 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 20:00 - 2014-04-02 20:00 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2014-04-02 20:00 - 2014-04-02 20:00 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-04-02 20:00 - 2014-04-02 20:00 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-04-02 20:00 - 2014-04-02 20:00 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2014-04-02 20:00 - 2014-04-02 20:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-04-02 20:00 - 2014-04-02 20:00 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2014-04-02 20:00 - 2014-04-02 20:00 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2014-04-02 20:00 - 2014-04-02 20:00 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-04-02 20:00 - 2014-04-02 20:00 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2014-04-02 18:19 - 2013-11-24 12:02 - 00000000 ____D () C:\Program Files\Windows Live
2014-04-02 18:19 - 2013-02-05 14:27 - 00000000 ____D () C:\Program Files (x86)\Windows Live
2014-04-02 16:43 - 2014-04-02 16:43 - 00000000 ____D () C:\Users\WIN7\AppData\Roaming\Avira
2014-04-02 16:42 - 2014-04-02 16:42 - 00002073 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk
2014-04-02 16:42 - 2014-04-02 16:42 - 00000000 ____D () C:\ProgramData\Avira
2014-04-02 16:42 - 2014-04-02 16:42 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-03-21 10:51 - 2014-03-21 10:51 - 01161872 _____ () C:\Windows\SysWOW64\MovieMode.48CA2AEFA22D.dll
Some content of TEMP:
====================
C:\Users\WIN7\AppData\Local\Temp\avgnt.exe
C:\Users\WIN7\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-25 13:22
==================== End Of Log ============================ --- --- ---
--- --- --- |