So,
dann mal alles ausgeführt. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 25.06.2014
Suchlauf-Zeit: 06:11:56
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.2.1012
Malware Datenbank: v2014.06.25.02
Rootkit Datenbank: v2014.06.23.02
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Self-protection: Deaktiviert
Betriebssystem: Windows 7 Service Pack 1
CPU: x64
Dateisystem: NTFS
Benutzer: FM
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 301412
Verstrichene Zeit: 16 Min, 49 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristics: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\updatetrolatunt.exe, 5932, Löschen bei Neustart, [aafc91eb116ae94dfbb0373b3bc65ca4]
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\utiltrolatunt.exe, 6088, Löschen bei Neustart, [c5e10e6e6516db5b0e9da6ccc43db947]
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\trolatunt.BrowserAdapter.exe, 3508, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61]
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\trolatunt.PurBrowse64.exe, 6024, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61]
Module: 3
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\FE0D7A37-7C9B-41C2-B2C8-1DB8D9D7A984.dll, Löschen bei Neustart, [d3d36a121e5d0630208a3c360af7f808],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\FE0D7A37-7C9B-41C2-B2C8-1DB8D9D7A984.dll, Löschen bei Neustart, [d3d36a121e5d0630208a3c360af7f808],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}.dll, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61],
Registrierungsschlüssel: 27
PUP.Optional.Trolatunt.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update trolatunt, In Quarantäne, [aafc91eb116ae94dfbb0373b3bc65ca4],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{59bc35cc-f3cb-4e2b-a21d-481d781207af}, In Quarantäne, [d3d36a121e5d0630208a3c360af7f808],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{59BC35CC-F3CB-4E2B-A21D-481D781207AF}, In Quarantäne, [d3d36a121e5d0630208a3c360af7f808],
PUP.Optional.Trolatunt.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{59BC35CC-F3CB-4E2B-A21D-481D781207AF}, Löschen bei Neustart, [d3d36a121e5d0630208a3c360af7f808],
PUP.Optional.Trolatunt.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{59BC35CC-F3CB-4E2B-A21D-481D781207AF}, Löschen bei Neustart, [d3d36a121e5d0630208a3c360af7f808],
PUP.Optional.Trolatunt.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util trolatunt, In Quarantäne, [c5e10e6e6516db5b0e9da6ccc43db947],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [792d4d2f0f6cd462e82c0b73bd45936d],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [792d4d2f0f6cd462e82c0b73bd45936d],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Löschen bei Neustart, [9c0a1468fb80bf77941ad07441c16d93],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\trolatunt, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{ac225167-00fc-452d-94c5-bb93600e7d9a}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, HKLM\SOFTWARE\WOW6432NODE\trolatunt, In Quarantäne, [4b5bd5a76615e056efb89b2349b938c8],
PUP.Optional.ConduitSearchProtect, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\CltMngSvc, In Quarantäne, [9610c7b5fe7dff37167be1ffc53e768a],
PUP.Optional.SearchProtect.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Conduit_Search_Protect, Löschen bei Neustart, [782e07757704ef4730a49f632ed6d729],
PUP.Optional.Trolatunt.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\trolatunt, Löschen bei Neustart, [fea8d2aad6a59b9b26828c3249b956aa],
PUP.Optional.PassShow.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\0AADCD53-E02F-9B5A-5431-BAACC6D75585, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.PassShow.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{26DAF52A-3157-01E3-88B1-1DE88DAE0CFD}, In Quarantäne, [53531f5d3a416ec89a58870283817090],
PUP.Optional.PassShow.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{26DAF52A-3157-01E3-88B1-1DE88DAE0CFD}, In Quarantäne, [53531f5d3a416ec89a58870283817090],
PUP.Optional.PassShow.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{26DAF52A-3157-01E3-88B1-1DE88DAE0CFD}, Löschen bei Neustart, [53531f5d3a416ec89a58870283817090],
PUP.Optional.PassShow.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{26DAF52A-3157-01E3-88B1-1DE88DAE0CFD}, Löschen bei Neustart, [53531f5d3a416ec89a58870283817090],
Registrierungswerte: 1
PUP.Optional.PassShow.A, HKU\S-1-5-21-1775333063-2312751946-3463116976-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MOZILLA\FIREFOX\EXTENSIONS|{BD4ACD0E-3854-3C2A-20FC-BC9B823C8DED}, C:\Program Files (x86)\PassShow-soft\171.xpi, Löschen bei Neustart, [f4b297e5df9cd066a42247644eb4d828]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 15
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\TEMP, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.OpenCandy, C:\Users\FM\AppData\Roaming\OpenCandy, In Quarantäne, [7630bac2ea91ac8aef1594fdd72b39c7],
PUP.Optional.OpenCandy, C:\Users\FM\AppData\Roaming\OpenCandy\27C7AE6F11FA470B905C54ED7F871BFA, In Quarantäne, [7630bac2ea91ac8aef1594fdd72b39c7],
PUP.Optional.OpenCandy, C:\Users\FM\AppData\Roaming\OpenCandy\571E786351284C92BC2264BC122E7136, In Quarantäne, [7630bac2ea91ac8aef1594fdd72b39c7],
PUP.Optional.OpenCandy, C:\Users\FM\AppData\Roaming\OpenCandy\C671CA7132FF40DC86A9B2EF3AC18FD7, In Quarantäne, [7630bac2ea91ac8aef1594fdd72b39c7],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect\rep, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect\STG, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\UI, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\UI\rep, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
Dateien: 52
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\updatetrolatunt.exe, Löschen bei Neustart, [aafc91eb116ae94dfbb0373b3bc65ca4],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\FE0D7A37-7C9B-41C2-B2C8-1DB8D9D7A984.dll, Löschen bei Neustart, [d3d36a121e5d0630208a3c360af7f808],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\utiltrolatunt.exe, Löschen bei Neustart, [c5e10e6e6516db5b0e9da6ccc43db947],
PUP.Optional.OpenCandy.A, C:\Users\FM\AppData\Roaming\OpenCandy\27C7AE6F11FA470B905C54ED7F871BFA\dlm.exe, In Quarantäne, [990d6c103e3d7abc7c8573b1f70a07f9],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Roaming\OpenCandy\27C7AE6F11FA470B905C54ED7F871BFA\SearchProtect_p1v3.exe, In Quarantäne, [85216319d4a79e988c11a6df3ac721df],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Roaming\OpenCandy\27C7AE6F11FA470B905C54ED7F871BFA\sp-downloader.exe, In Quarantäne, [d2d494e86516eb4babf2473e46bbb947],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Roaming\OpenCandy\571E786351284C92BC2264BC122E7136\Search_Protect_non_G.exe, In Quarantäne, [357186f6c4b7b680dfbe96ef917045bb],
PUP.Optional.OpenCandy.A, C:\Users\FM\AppData\Roaming\OpenCandy\C671CA7132FF40DC86A9B2EF3AC18FD7\dlm.exe, In Quarantäne, [8e18235990eb2b0b7f82af7555acc040],
PUP.Optional.PassShow.A, C:\Windows\System32\Tasks\PassShow Update, In Quarantäne, [e1c5adcf1b6065d15019cfda5ea4a25e],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\trolatunt.ico, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\0, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\7za.exe, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\trolatunt.FirstRun.exe, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\trolatuntUn.exe, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\trolatuntUninstall.exe, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\updatetrolatunt.InstallState, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\7za.exe, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\BrowserAdapterS.7z, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\trolatunt.BrowserAdapter.exe, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\trolatunt.PurBrowse64.exe, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\trolatunt.PurBrowseG.zip, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\trolatuntBAApp.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\utiltrolatunt.InstallState, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}.dll, Löschen bei Neustart, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.Bromon.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.BroStats.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.BrowserAdapterS.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.CompatibilityChecker.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.FFUpdate.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.IEUpdate.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.PurBrowseG.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.Trolatunt.A, C:\Program Files (x86)\trolatunt\bin\plugins\trolatunt.Repmon.dll, In Quarantäne, [a303a6d695e65bdb624486382fd39f61],
PUP.Optional.PassShow.A, C:\Windows\Tasks\PassShow Update.job, In Quarantäne, [a8fe26563546ee486cece9e412f0966a],
PUP.Optional.QuickStart.A, C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pelmeidfhdlhlbjimpabfcbnnojbboma_0.localstorage, In Quarantäne, [c3e34c3080fb0c2abc177290020252ae],
PUP.Optional.OpenCandy, C:\Users\FM\AppData\Roaming\OpenCandy\C671CA7132FF40DC86A9B2EF3AC18FD7\TuneUp2014GER15day-de-DE-p4v1.exe, In Quarantäne, [7630bac2ea91ac8aef1594fdd72b39c7],
PUP.Optional.OpenCandy, C:\Users\FM\AppData\Roaming\OpenCandy\C671CA7132FF40DC86A9B2EF3AC18FD7\TuneUpUtilities2014_de-DE.exe, In Quarantäne, [7630bac2ea91ac8aef1594fdd72b39c7],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft\171.dat, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft\171.xpi, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft\a.db, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft\b.db, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft\PassShown90.exe, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft\Sqlite3.dll, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.PassShow.A, C:\Program Files (x86)\PassShow-soft\Uninstall.exe, In Quarantäne, [aafcd7a5f784c76fb2ca8717a2607789],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect\CRASH_DUMP_P6252_T3952_D2014_06_24_T16_00_38.dmp, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect\CRASH_REPORT_P6252_T3952_D2014_06_24_T16_00_38.txt, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect\rep\Cvc.dat, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect\rep\UserRepository.dat, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\SearchProtect\rep\UserSettings.dat, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.SearchProtect.A, C:\Users\FM\AppData\Local\SearchProtect\UI\rep\UIRepository.dat, In Quarantäne, [802625570477ac8a4fa936709c665aa6],
PUP.Optional.Trovi.A, C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "startup_urls": [ "hxxp://www.trovi.com/?gd=&ctid=CT3320691&octid=EB_ORIGINAL_CTID&ISID=ME6E4F5E8-1AC6-4BD6-9C18-8D174EA9F046&SearchSource=55&CUI=&UM=5&UP=SPE7F77C52-C2FF-42EB-99CB-D0A1EA299005&SSPV=" ],), Ersetzt,[2d79b6c6eb9004320cf3f7bcbc48a55b]
PUP.Optional.Trovi.A, C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "homepage": "hxxp://www.trovi.com/?gd=&ctid=CT3320691&octid=EB_ORIGINAL_CTID&ISID=ME6E4F5E8-1AC6-4BD6-9C18-8D174EA9F046&SearchSource=55&CUI=&UM=5&UP=SPE7F77C52-C2FF-42EB-99CB-D0A1EA299005&SSPV=",), Ersetzt,[9d09d9a3c6b588ae08f85460f80c55ab]
PUP.Optional.Trovi.A, C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Preferences, Gut: (), Schlecht: ( "search_url": "hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3320691&octid=EB_ORIGINAL_CTID&ISID=ME6E4F5E8-1AC6-4BD6-9C18-8D174EA9F046&SearchSource=58&CUI=&UM=5&UP=SPE7F77C52-C2FF-42EB-99CB-D0A1EA299005&q={searchTerms}&SSPV=",), Ersetzt,[2284790388f3181eb54c288c9e6633cd]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.213 - Bericht erstellt am 25/06/2014 um 07:36:48
# Aktualisiert 23/06/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : FM - FM-PC
# Gestartet von : C:\Users\FM\Downloads\adwcleaner_3.213.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKCU\Software\Myfree Codec
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKLM\Software\Myfree Codec
Schlüssel Gelöscht : HKLM\Software\SearchProtect
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17126
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3320691&octid=EB_ORIGINAL_CTID&ISID=ME6E4F5E8-1AC6-4BD6-9C18-8D174EA9F046&SearchSource=58&CUI=&UM=5&UP=SPE7F77C52-C2FF-42EB-99CB-D0A1EA299005&q={searchTerms}&SSPV=
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
Gelöscht [Extension] : mkcedibhemacmilmkpndpkoidlnmgngg
*************************
AdwCleaner[R0].txt - [1890 octets] - [25/06/2014 07:03:07]
AdwCleaner[S0].txt - [1710 octets] - [25/06/2014 07:36:48]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1770 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by FM on 25.06.2014 at 7:49:45,57
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-1775333063-2312751946-3463116976-1001\Software\wajam
~~~ Files
Successfully deleted: [File] "C:\Users\FM\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\Program Files (x86)\myfree codec"
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{00319B8C-DA0C-4726-A346-D15A2B27A344}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{2B2E4A18-2AAC-41E8-85E9-00C40334C3C3}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{35ED53D9-E12B-4136-B9D4-AF0D1B3CAA3B}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{408BA467-41B2-472D-9AD5-812E28D33B5C}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{59A7FE9F-7C34-4A79-96FD-21B757CA7FF9}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{64593948-DD3E-45A2-B124-D013CF0A1CD8}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{8762DA4A-749E-4FAC-A5FF-EC6767CC268F}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{8CC20577-C43F-4D8A-B376-B32E81CB6465}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{905F471B-2F5A-4B3F-AF7C-EF88F2B85075}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{9DEB5727-3F98-4134-B41C-EA629DF70DF0}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{A00112E4-ECC8-4575-BCA8-5E85D1B38A0C}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{A03ACC7A-894F-4059-8859-109ECD67C3F0}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{BD149C4E-58FF-4F6B-87B4-BE8EE3496421}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{BECDD176-1FF6-4CA0-A920-55B123D356AC}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{CAD077BE-275D-4E87-91AA-210BDB27DA6E}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{D1BCB470-2985-4C9D-A9B1-3495225BF147}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{D40F0EBE-4058-4EE7-8DCC-F259D86F10B0}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{D99F670C-D2D4-424A-9A0A-8B5D9D0E39A3}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{DBC22A06-A6B0-420F-B138-003E91510BE7}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{DBCA010F-EF04-41A3-BEE9-393B865EE594}
Successfully deleted: [Empty Folder] C:\Users\FM\appdata\local\{E5D7C0A5-9FB3-46EF-B351-4609EE6A59E8}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 25.06.2014 at 7:57:17,35
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-06-2014
Ran by FM (administrator) on FM-PC on 25-06-2014 09:26:27
Running from C:\Users\FM\Downloads
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
( ) C:\Windows\System32\lxcqcoms.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NTI, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\HelperService.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect\ConversionService.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
() C:\Program Files (x86)\Time Inspector\TimeInspector.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Primax Electronics Ltd.) C:\Windows\System32\ICO.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Primax Electronics Ltd.) C:\Windows\System32\PELMICED.EXE
() C:\Program Files (x86)\Lexmark 9300 Series\lxcqmon.exe
(Lexmark International Inc.) C:\Program Files (x86)\Lexmark 9300 Series\ezprint.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Samsung) C:\Program Files (x86)\Samsung\Kies\Kies.exe
(Spotify Ltd) C:\Users\FM\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Dropbox, Inc.) C:\Users\FM\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Farbar) C:\Users\FM\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] => C:\Program Files\Elantech\ETDCtrl.exe [649608 2010-04-13] (ELAN Microelectronic Corp.)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [860040 2011-01-05] (Acer Incorporated)
HKLM\...\Run: [Mouse Suite 98 Daemon] => C:\Windows\system32\ICO.EXE [90624 2006-09-29] (Primax Electronics Ltd.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1271072 2014-03-11] (Microsoft Corporation)
HKLM\...\Run: [lxcqmon.exe] => C:\Program Files (x86)\Lexmark 9300 Series\lxcqmon.exe [291760 2007-01-11] ()
HKLM\...\Run: [EzPrint] => C:\Program Files (x86)\Lexmark 9300 Series\ezprint.exe [82864 2006-12-05] (Lexmark International Inc.)
HKLM\...\Run: [LXCQCATS] => C:\Windows\system32\spool\DRIVERS\x64\3\LXCQtime.dll [31744 2006-11-21] (Lexmark International Inc.)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-04-13] (Intel Corporation)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-02] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [265984 2010-06-29] (NewTech Infosystems, Inc.)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [975952 2010-08-10] (Dritek System Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [737872 2014-05-22] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [310064 2014-05-28] (Samsung Electronics Co., Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1775333063-2312751946-3463116976-1001\...\Run: [KiesPreload] => C:\Program Files (x86)\Samsung\Kies\Kies.exe [1563440 2014-05-28] (Samsung)
HKU\S-1-5-21-1775333063-2312751946-3463116976-1001\...\Run: [Spotify] => C:\Users\FM\AppData\Roaming\Spotify\Spotify.exe [6170168 2014-05-23] (Spotify Ltd)
HKU\S-1-5-21-1775333063-2312751946-3463116976-1001\...\Run: [Spotify Web Helper] => C:\Users\FM\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-23] (Spotify Ltd)
HKU\S-1-5-21-1775333063-2312751946-3463116976-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248176 2014-06-05] (TomTom)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk
ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\FM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\FM\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\FM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk
ShortcutTarget: OneNote 2010 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 1 (GFS Unread Stub) -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 2 (GFS Stub) -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 3 (GFS Folder) -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: Groove Explorer Icon Overlay 4 (GFS Unread Mark) -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => No File
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 1 (GFS Unread Stub) -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 2 (GFS Stub) -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 2.5 (GFS Unread Folder) -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 3 (GFS Folder) -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: Groove Explorer Icon Overlay 4 (GFS Unread Mark) -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BootExecute: autocheck autochk * sdnclean64.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GmbH)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Acer\Acer VCM\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @mcafee.com/SAFFPlugin - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll No File
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - C:\Program Files\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt [2013-09-16]
Chrome:
=======
CHR HomePage:
CHR NewTab: "chrome-extension://pelmeidfhdlhlbjimpabfcbnnojbboma/index.html"
CHR DefaultSearchKeyword: trovi.search
CHR DefaultSearchProvider: Trovi search
CHR DefaultNewTabURL:
CHR Extension: (Google Docs) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-01-28]
CHR Extension: (Google Drive) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-01-28]
CHR Extension: (YouTube) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-01-28]
CHR Extension: (Google-Suche) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-01-28]
CHR Extension: (No Name) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg [2014-05-15]
CHR Extension: (Securita Scout) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfkilfadjoneaheacgmkahfgcjchkpad [2014-03-24]
CHR Extension: (Google Wallet) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-01-28]
CHR Extension: (Google Mail) - C:\Users\FM\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-01-28]
CHR HKLM-x32\...\Chrome\Extension: [gmbgjmbmhjnohlgodljefenjodcilgdo] - C:\ProgramData\SaveByclick\gmbgjmbmhjnohlgodljefenjodcilgdo.crx [2014-01-28]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-05-22] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [1039440 2014-05-22] (Avira Operations GmbH & Co. KG)
R2 lxcq_device; C:\Windows\system32\lxcqcoms.exe [566192 2006-12-05] ( )
R2 lxcq_device; C:\Windows\SysWOW64\lxcqcoms.exe [537520 2006-12-05] ( )
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2014-03-11] (Microsoft Corporation)
S3 MSSQL$MSSMLBIZ; C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.MSSMLBIZ\MSSQL\Binn\sqlservr.exe [43028328 2011-09-22] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [347872 2014-03-11] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-02] (Symantec Corporation)
R2 NTISchedulerSvc; C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144640 2010-04-17] (NTI, Inc.)
R2 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1320496 2013-04-08] (pdfforge GmbH)
R2 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [799280 2013-04-08] (pdfforge GmbH)
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [260640 2010-01-29] (Acer Incorporated)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
S4 SQLAgent$MSSMLBIZ; C:\Program Files (x86)\Microsoft SQL Server\MSSQL10.MSSMLBIZ\MSSQL\Binn\SQLAGENT.EXE [370024 2011-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [112080 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-11-14] (Avira Operations GmbH & Co. KG)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-06-25] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [268512 2014-01-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133928 2014-03-11] (Microsoft Corporation)
R3 pelmouse; C:\Windows\System32\DRIVERS\pelmouse.sys [25600 2007-04-13] (Primax Electronics Ltd.)
R3 pelusblf; C:\Windows\System32\DRIVERS\pelusblf.sys [21504 2007-04-13] (Primax Electronics Ltd.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R1 {0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64; C:\Windows\System32\drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64.sys [61112 2014-06-09] (StdLib)
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-06-25 07:57 - 2014-06-25 07:57 - 00003234 _____ () C:\Users\FM\Desktop\JRT.txt
2014-06-25 07:40 - 2014-06-25 07:40 - 00001850 _____ () C:\Users\FM\Desktop\AdwCleaner[S0].txt
2014-06-25 07:02 - 2014-06-25 07:36 - 00000000 ____D () C:\AdwCleaner
2014-06-25 07:02 - 2014-06-25 07:02 - 01342659 _____ () C:\Users\FM\Downloads\adwcleaner_3.213.exe
2014-06-25 07:02 - 2014-06-25 07:02 - 00017635 _____ () C:\Users\FM\Desktop\mbam.txt
2014-06-25 06:33 - 2014-06-25 06:35 - 00000794 _____ () C:\Windows\SecuniaPackage.log
2014-06-25 06:09 - 2014-06-25 06:10 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\FM\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-24 16:21 - 2014-06-24 16:21 - 00037497 _____ () C:\ComboFix.txt
2014-06-24 15:33 - 2014-06-24 16:22 - 00000000 ____D () C:\Qoobox
2014-06-24 15:33 - 2014-06-24 16:22 - 00000000 ____D () C:\ComboFix
2014-06-24 15:33 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-06-24 15:33 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-06-24 15:33 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-06-24 15:33 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-06-24 15:33 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-06-24 15:33 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-06-24 15:33 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-06-24 15:33 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-06-24 15:32 - 2014-06-24 16:16 - 00000000 ____D () C:\Windows\erdnt
2014-06-24 15:30 - 2014-06-24 15:32 - 05211571 ____R (Swearware) C:\Users\FM\Desktop\ComboFix.exe
2014-06-24 11:22 - 2014-06-24 11:22 - 00003250 _____ () C:\Windows\System32\Tasks\{15BE794D-F26E-4F88-B7A1-10FCF3423993}
2014-06-24 10:36 - 2014-06-24 10:36 - 00001272 _____ () C:\Users\FM\Desktop\Revo Uninstaller.lnk
2014-06-24 10:36 - 2014-06-24 10:36 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-24 10:35 - 2014-06-24 10:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\FM\Downloads\revosetup95.exe
2014-06-24 10:12 - 2014-06-24 10:12 - 02082816 _____ (Farbar) C:\Users\FM\Downloads\FRST64 (1).exe
2014-06-17 15:27 - 2014-06-24 10:18 - 00043662 _____ () C:\Users\FM\Downloads\Addition.txt
2014-06-17 15:25 - 2014-06-25 09:27 - 00022750 _____ () C:\Users\FM\Downloads\FRST.txt
2014-06-17 15:25 - 2014-06-25 09:26 - 00000000 ____D () C:\FRST
2014-06-17 15:24 - 2014-06-17 15:25 - 02081280 _____ (Farbar) C:\Users\FM\Downloads\FRST64.exe
2014-06-17 13:55 - 2014-06-17 14:09 - 00000000 ____D () C:\Users\FM\AppData\Roaming\vlc
2014-06-17 13:53 - 2014-06-17 13:53 - 00001074 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-06-17 13:53 - 2014-06-17 13:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-06-17 13:52 - 2014-06-17 13:52 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-06-17 13:49 - 2014-06-17 13:49 - 00961360 _____ (Chip Digital GmbH) C:\Users\FM\Downloads\VLC media player 32 Bit - CHIP-Installer.exe
2014-06-17 12:28 - 2014-06-25 07:39 - 00000000 ____D () C:\Users\FM\AppData\Roaming\FileAdvisor
2014-06-17 12:27 - 2014-06-17 19:22 - 00000000 ____D () C:\Users\FM\Desktop\1
2014-06-17 11:46 - 2014-06-25 06:54 - 00000000 ____D () C:\Users\FM\AppData\Roaming\DVDVideoSoft
2014-06-17 11:40 - 2014-06-17 11:45 - 32739456 _____ (DVDVideoSoft Ltd. ) C:\Users\FM\Downloads\FreeMP4VideoConverter5.0.43.605.exe
2014-06-17 11:05 - 2014-06-14 18:39 - 2745683427 ____N () C:\Users\FM\Desktop\20140614_181749.mp4
2014-06-17 10:38 - 2014-06-17 10:38 - 00002010 _____ () C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-06-17 10:37 - 2014-04-11 10:39 - 00206080 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudmdm.sys
2014-06-17 10:37 - 2014-04-11 10:39 - 00110336 _____ (DEVGURU Co., LTD.(www.devguru.co.kr)) C:\Windows\system32\Drivers\ssudbus.sys
2014-06-17 10:12 - 2014-06-17 10:12 - 00000000 ____D () C:\Program Files (x86)\Lame For Audacity
2014-06-17 10:11 - 2014-06-17 10:12 - 00527423 _____ ( ) C:\Users\FM\Downloads\Lame_v3.99.3_for_Windows.exe
2014-06-17 09:44 - 2014-06-17 09:48 - 00000000 ____D () C:\Program Files (x86)\MP3Gain
2014-06-17 09:44 - 2014-06-17 09:44 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3Gain
2014-06-17 09:44 - 2014-06-17 09:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3Gain
2014-06-17 09:42 - 2014-06-17 09:43 - 00667344 _____ () C:\Users\FM\Downloads\mp3gain-win-1_2_5.exe
2014-06-16 13:26 - 2014-06-09 11:54 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64.sys
2014-06-16 12:45 - 2014-06-16 12:45 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler
2014-06-16 12:45 - 2014-06-16 12:45 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-06-16 12:30 - 2014-06-16 12:30 - 00000000 ____D () C:\Users\FM\AppData\Roaming\TuneUp Software
2014-06-16 12:30 - 2014-06-16 12:30 - 00000000 ____D () C:\Users\FM\AppData\Local\TuneUp Software
2014-06-16 12:29 - 2014-06-16 12:42 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-06-16 12:29 - 2014-06-16 12:33 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-06-16 12:28 - 2014-06-16 13:14 - 00000000 ____D () C:\Users\FM\AppData\Roaming\AdvertismentImages
2014-06-16 12:27 - 2014-06-25 07:50 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Time Inspector
2014-06-16 12:27 - 2014-06-16 12:27 - 00003222 _____ () C:\Windows\System32\Tasks\TimeInspectorRun
2014-06-16 12:27 - 2014-06-16 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Time Inspector
2014-06-16 12:27 - 2014-06-16 12:27 - 00000000 ____D () C:\Program Files (x86)\Time Inspector
2014-06-16 12:21 - 2014-06-16 12:21 - 00929416 _____ (CNET Download.com) C:\Users\FM\Downloads\cbsidlm-cbsi188-Free_M4a_to_MP3_Converter-BP-187723.exe
2014-06-16 12:20 - 2014-06-24 15:28 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2014-06-16 12:20 - 2014-06-16 12:27 - 00003564 _____ () C:\Windows\System32\Tasks\FileAdvisorUpdate
2014-06-16 12:20 - 2014-06-16 12:27 - 00003510 _____ () C:\Windows\System32\Tasks\FileAdvisorCheck
2014-06-16 12:20 - 2014-06-16 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor
2014-06-13 07:06 - 2014-05-30 12:21 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-13 07:06 - 2014-05-30 12:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-13 07:06 - 2014-05-30 12:02 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-13 07:06 - 2014-05-30 11:45 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-13 07:06 - 2014-05-30 11:39 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-13 07:06 - 2014-05-30 11:39 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-13 07:06 - 2014-05-30 11:38 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-13 07:06 - 2014-05-30 11:28 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-13 07:06 - 2014-05-30 11:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-13 07:06 - 2014-05-30 11:24 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-13 07:06 - 2014-05-30 11:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-13 07:06 - 2014-05-30 11:21 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-13 07:06 - 2014-05-30 11:20 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-13 07:06 - 2014-05-30 11:18 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-13 07:06 - 2014-05-30 11:11 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-13 07:06 - 2014-05-30 11:08 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-13 07:06 - 2014-05-30 11:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-13 07:06 - 2014-05-30 11:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-13 07:06 - 2014-05-30 10:55 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-13 07:06 - 2014-05-30 10:49 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-13 07:06 - 2014-05-30 10:46 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-13 07:06 - 2014-05-30 10:44 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-13 07:06 - 2014-05-30 10:44 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-13 07:06 - 2014-05-30 10:43 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-13 07:06 - 2014-05-30 10:42 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-13 07:06 - 2014-05-30 10:38 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-13 07:06 - 2014-05-30 10:35 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-13 07:06 - 2014-05-30 10:34 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-13 07:06 - 2014-05-30 10:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-13 07:06 - 2014-05-30 10:30 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-13 07:06 - 2014-05-30 10:29 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-13 07:06 - 2014-05-30 10:28 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-13 07:06 - 2014-05-30 10:27 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-13 07:06 - 2014-05-30 10:24 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-13 07:06 - 2014-05-30 10:23 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-13 07:06 - 2014-05-30 10:16 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-13 07:06 - 2014-05-30 10:10 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-13 07:06 - 2014-05-30 10:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-13 07:06 - 2014-05-30 10:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-13 07:06 - 2014-05-30 10:02 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-13 07:06 - 2014-05-30 09:56 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-13 07:06 - 2014-05-30 09:56 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-13 07:06 - 2014-05-30 09:54 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-13 07:06 - 2014-05-30 09:50 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-13 07:06 - 2014-05-30 09:49 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-13 07:06 - 2014-05-30 09:43 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-13 07:06 - 2014-05-30 09:40 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-13 07:06 - 2014-05-30 09:30 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-13 07:06 - 2014-05-30 09:21 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-13 07:06 - 2014-05-30 09:15 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-13 07:06 - 2014-05-30 09:13 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-13 07:06 - 2014-05-30 09:13 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-12 17:45 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-12 17:45 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-12 17:45 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-12 17:45 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-12 17:45 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-12 17:45 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-12 17:45 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-12 17:45 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-12 17:45 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-12 17:45 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-12 17:45 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-12 17:45 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-12 17:45 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-12 17:45 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-12 17:42 - 2014-06-12 17:42 - 00000000 ____D () C:\Users\FM\Documents\TomTom
2014-06-12 17:42 - 2014-06-12 17:42 - 00000000 ____D () C:\ProgramData\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Users\FM\AppData\Roaming\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Mozilla
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Users\FM\AppData\Local\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Program Files (x86)\TomTom HOME 2
2014-06-12 17:39 - 2014-06-12 17:39 - 00000000 ____D () C:\Program Files (x86)\TomTom International B.V
2014-06-12 17:39 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-12 17:39 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-06-12 17:25 - 2014-06-12 17:36 - 31119112 _____ () C:\Users\FM\Downloads\TomTomHOME2winlatest.exe
2014-05-30 19:09 - 2014-06-25 06:11 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-30 19:09 - 2014-06-25 06:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-30 19:08 - 2014-06-25 06:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-30 19:08 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-30 19:08 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-30 19:08 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
==================== One Month Modified Files and Folders =======
2014-06-25 09:27 - 2014-06-17 15:25 - 00022750 _____ () C:\Users\FM\Downloads\FRST.txt
2014-06-25 09:26 - 2014-06-17 15:25 - 00000000 ____D () C:\FRST
2014-06-25 09:00 - 2011-11-29 20:07 - 01873035 _____ () C:\Windows\WindowsUpdate.log
2014-06-25 08:50 - 2014-01-20 16:43 - 00001102 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-06-25 08:42 - 2012-06-28 22:21 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-06-25 07:57 - 2014-06-25 07:57 - 00003234 _____ () C:\Users\FM\Desktop\JRT.txt
2014-06-25 07:50 - 2014-06-16 12:27 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Time Inspector
2014-06-25 07:49 - 2014-05-18 17:08 - 00000000 ____D () C:\Windows\ERUNT
2014-06-25 07:46 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-06-25 07:46 - 2009-07-14 06:45 - 00016976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-06-25 07:41 - 2014-03-11 15:58 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Spotify
2014-06-25 07:40 - 2014-06-25 07:40 - 00001850 _____ () C:\Users\FM\Desktop\AdwCleaner[S0].txt
2014-06-25 07:39 - 2014-06-17 12:28 - 00000000 ____D () C:\Users\FM\AppData\Roaming\FileAdvisor
2014-06-25 07:39 - 2014-05-14 12:34 - 00000000 ____D () C:\Users\FM\AppData\Roaming\DropboxMaster
2014-06-25 07:39 - 2013-12-03 13:52 - 00000433 _____ () C:\Windows\system32\Drivers\etc\hosts.ics
2014-06-25 07:39 - 2013-06-03 19:49 - 00000000 ___RD () C:\Users\FM\Dropbox
2014-06-25 07:39 - 2013-06-03 19:46 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Dropbox
2014-06-25 07:38 - 2014-01-20 16:43 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-06-25 07:38 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-06-25 07:38 - 2009-07-14 06:51 - 00080953 _____ () C:\Windows\setupact.log
2014-06-25 07:37 - 2010-11-21 05:47 - 00367340 _____ () C:\Windows\PFRO.log
2014-06-25 07:36 - 2014-06-25 07:02 - 00000000 ____D () C:\AdwCleaner
2014-06-25 07:02 - 2014-06-25 07:02 - 01342659 _____ () C:\Users\FM\Downloads\adwcleaner_3.213.exe
2014-06-25 07:02 - 2014-06-25 07:02 - 00017635 _____ () C:\Users\FM\Desktop\mbam.txt
2014-06-25 07:00 - 2014-05-15 11:37 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-06-25 06:54 - 2014-06-17 11:46 - 00000000 ____D () C:\Users\FM\AppData\Roaming\DVDVideoSoft
2014-06-25 06:35 - 2014-06-25 06:33 - 00000794 _____ () C:\Windows\SecuniaPackage.log
2014-06-25 06:35 - 2014-03-11 16:00 - 00000000 ____D () C:\Users\FM\AppData\Local\Spotify
2014-06-25 06:34 - 2012-06-28 22:21 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-06-25 06:34 - 2012-04-10 22:36 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-06-25 06:34 - 2012-04-10 22:36 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-06-25 06:32 - 2013-03-24 10:16 - 00000000 ____D () C:\Program Files\Lx_cats
2014-06-25 06:30 - 2009-07-14 04:34 - 00000580 _____ () C:\Windows\win.ini
2014-06-25 06:11 - 2014-05-30 19:09 - 00001110 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-06-25 06:11 - 2014-05-30 19:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-06-25 06:11 - 2014-05-30 19:08 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-06-25 06:10 - 2014-06-25 06:09 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\FM\Downloads\mbam-setup-2.0.2.1012.exe
2014-06-24 16:22 - 2014-06-24 15:33 - 00000000 ____D () C:\Qoobox
2014-06-24 16:22 - 2014-06-24 15:33 - 00000000 ____D () C:\ComboFix
2014-06-24 16:22 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default
2014-06-24 16:21 - 2014-06-24 16:21 - 00037497 _____ () C:\ComboFix.txt
2014-06-24 16:16 - 2014-06-24 15:32 - 00000000 ____D () C:\Windows\erdnt
2014-06-24 16:05 - 2009-07-14 04:34 - 00000215 _____ () C:\Windows\system.ini
2014-06-24 16:00 - 2013-03-24 16:09 - 00000000 ____D () C:\Users\FM\Documents\Outlook-Dateien
2014-06-24 15:53 - 2012-03-11 20:22 - 00000000 ____D () C:\Users\FM
2014-06-24 15:32 - 2014-06-24 15:30 - 05211571 ____R (Swearware) C:\Users\FM\Desktop\ComboFix.exe
2014-06-24 15:28 - 2014-06-16 12:20 - 00000000 ____D () C:\Program Files (x86)\File Type Advisor
2014-06-24 15:28 - 2012-03-11 21:01 - 00003906 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896}
2014-06-24 11:22 - 2014-06-24 11:22 - 00003250 _____ () C:\Windows\System32\Tasks\{15BE794D-F26E-4F88-B7A1-10FCF3423993}
2014-06-24 10:36 - 2014-06-24 10:36 - 00001272 _____ () C:\Users\FM\Desktop\Revo Uninstaller.lnk
2014-06-24 10:36 - 2014-06-24 10:36 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-06-24 10:35 - 2014-06-24 10:35 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\FM\Downloads\revosetup95.exe
2014-06-24 10:18 - 2014-06-17 15:27 - 00043662 _____ () C:\Users\FM\Downloads\Addition.txt
2014-06-24 10:12 - 2014-06-24 10:12 - 02082816 _____ (Farbar) C:\Users\FM\Downloads\FRST64 (1).exe
2014-06-23 13:45 - 2014-01-20 16:43 - 00004098 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-23 13:45 - 2014-01-20 16:43 - 00003846 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-17 19:22 - 2014-06-17 12:27 - 00000000 ____D () C:\Users\FM\Desktop\1
2014-06-17 15:25 - 2014-06-17 15:24 - 02081280 _____ (Farbar) C:\Users\FM\Downloads\FRST64.exe
2014-06-17 15:08 - 2011-11-30 04:57 - 00765446 _____ () C:\Windows\system32\perfh007.dat
2014-06-17 15:08 - 2011-11-30 04:57 - 00174226 _____ () C:\Windows\system32\perfc007.dat
2014-06-17 15:08 - 2009-07-14 07:13 - 01805178 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-06-17 14:09 - 2014-06-17 13:55 - 00000000 ____D () C:\Users\FM\AppData\Roaming\vlc
2014-06-17 13:53 - 2014-06-17 13:53 - 00001074 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-06-17 13:53 - 2014-06-17 13:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2014-06-17 13:52 - 2014-06-17 13:52 - 00000000 ____D () C:\Program Files (x86)\VideoLAN
2014-06-17 13:50 - 2013-11-05 17:37 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Audacity
2014-06-17 13:49 - 2014-06-17 13:49 - 00961360 _____ (Chip Digital GmbH) C:\Users\FM\Downloads\VLC media player 32 Bit - CHIP-Installer.exe
2014-06-17 13:07 - 2012-03-11 20:24 - 00000000 ____D () C:\Users\FM\AppData\Local\VirtualStore
2014-06-17 11:45 - 2014-06-17 11:40 - 32739456 _____ (DVDVideoSoft Ltd. ) C:\Users\FM\Downloads\FreeMP4VideoConverter5.0.43.605.exe
2014-06-17 11:36 - 2014-05-22 15:52 - 00163840 ___SH () C:\Users\FM\Desktop\Thumbs.db
2014-06-17 10:38 - 2014-06-17 10:38 - 00002010 _____ () C:\Users\Public\Desktop\Samsung Kies (Lite).lnk
2014-06-17 10:29 - 2013-07-13 19:43 - 00000000 ____D () C:\Program Files (x86)\MarkAny
2014-06-17 10:12 - 2014-06-17 10:12 - 00000000 ____D () C:\Program Files (x86)\Lame For Audacity
2014-06-17 10:12 - 2014-06-17 10:11 - 00527423 _____ ( ) C:\Users\FM\Downloads\Lame_v3.99.3_for_Windows.exe
2014-06-17 09:48 - 2014-06-17 09:44 - 00000000 ____D () C:\Program Files (x86)\MP3Gain
2014-06-17 09:44 - 2014-06-17 09:44 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3Gain
2014-06-17 09:44 - 2014-06-17 09:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3Gain
2014-06-17 09:43 - 2014-06-17 09:42 - 00667344 _____ () C:\Users\FM\Downloads\mp3gain-win-1_2_5.exe
2014-06-16 14:17 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-06-16 13:14 - 2014-06-16 12:28 - 00000000 ____D () C:\Users\FM\AppData\Roaming\AdvertismentImages
2014-06-16 12:45 - 2014-06-16 12:45 - 00003704 _____ () C:\Windows\System32\Tasks\Java Update Scheduler
2014-06-16 12:45 - 2014-06-16 12:45 - 00003694 _____ () C:\Windows\System32\Tasks\Adobe-Online-Aktualisierungsprogramm
2014-06-16 12:42 - 2014-06-16 12:29 - 00000000 __SHD () C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2014-06-16 12:42 - 2013-04-27 21:13 - 00000000 ____D () C:\Users\FM\AppData\Local\Downloaded Installations
2014-06-16 12:42 - 2012-04-10 20:34 - 00000000 ____D () C:\Users\FM\AppData\Local\Microsoft Help
2014-06-16 12:33 - 2014-06-16 12:29 - 00000000 ____D () C:\ProgramData\TuneUp Software
2014-06-16 12:30 - 2014-06-16 12:30 - 00000000 ____D () C:\Users\FM\AppData\Roaming\TuneUp Software
2014-06-16 12:30 - 2014-06-16 12:30 - 00000000 ____D () C:\Users\FM\AppData\Local\TuneUp Software
2014-06-16 12:27 - 2014-06-16 12:27 - 00003222 _____ () C:\Windows\System32\Tasks\TimeInspectorRun
2014-06-16 12:27 - 2014-06-16 12:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Time Inspector
2014-06-16 12:27 - 2014-06-16 12:27 - 00000000 ____D () C:\Program Files (x86)\Time Inspector
2014-06-16 12:27 - 2014-06-16 12:20 - 00003564 _____ () C:\Windows\System32\Tasks\FileAdvisorUpdate
2014-06-16 12:27 - 2014-06-16 12:20 - 00003510 _____ () C:\Windows\System32\Tasks\FileAdvisorCheck
2014-06-16 12:27 - 2014-06-16 12:20 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\File Type Advisor
2014-06-16 12:21 - 2014-06-16 12:21 - 00929416 _____ (CNET Download.com) C:\Users\FM\Downloads\cbsidlm-cbsi188-Free_M4a_to_MP3_Converter-BP-187723.exe
2014-06-14 22:51 - 2013-07-26 12:31 - 00000000 ____D () C:\Windows\system32\MRT
2014-06-14 22:45 - 2012-03-11 21:05 - 95414520 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-06-14 18:39 - 2014-06-17 11:05 - 2745683427 ____N () C:\Users\FM\Desktop\20140614_181749.mp4
2014-06-13 09:03 - 2012-04-10 20:33 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-13 09:02 - 2014-05-07 10:32 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-12 17:42 - 2014-06-12 17:42 - 00000000 ____D () C:\Users\FM\Documents\TomTom
2014-06-12 17:42 - 2014-06-12 17:42 - 00000000 ____D () C:\ProgramData\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Users\FM\AppData\Roaming\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Mozilla
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Users\FM\AppData\Local\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2014-06-12 17:41 - 2014-06-12 17:41 - 00000000 ____D () C:\Program Files (x86)\TomTom HOME 2
2014-06-12 17:39 - 2014-06-12 17:39 - 00000000 ____D () C:\Program Files (x86)\TomTom International B.V
2014-06-12 17:36 - 2014-06-12 17:25 - 31119112 _____ () C:\Users\FM\Downloads\TomTomHOME2winlatest.exe
2014-06-11 14:27 - 2012-04-01 17:07 - 00000000 ____D () C:\Users\FM\Desktop\Geschäft
2014-06-09 11:54 - 2014-06-16 13:26 - 00061112 _____ (StdLib) C:\Windows\system32\Drivers\{0c0bb4a8-45a4-4685-9c1d-08d98af4b926}Gw64.sys
2014-06-08 11:13 - 2014-06-12 17:39 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-08 11:08 - 2014-06-12 17:39 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-05-30 12:21 - 2014-06-13 07:06 - 23414784 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-30 12:02 - 2014-06-13 07:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-30 12:02 - 2014-06-13 07:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-05-30 11:45 - 2014-06-13 07:06 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-05-30 11:39 - 2014-06-13 07:06 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-05-30 11:39 - 2014-06-13 07:06 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-05-30 11:38 - 2014-06-13 07:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-05-30 11:28 - 2014-06-13 07:06 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-05-30 11:27 - 2014-06-13 07:06 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-05-30 11:24 - 2014-06-13 07:06 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-05-30 11:21 - 2014-06-13 07:06 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-05-30 11:21 - 2014-06-13 07:06 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-05-30 11:20 - 2014-06-13 07:06 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-05-30 11:18 - 2014-06-13 07:06 - 17271296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-30 11:11 - 2014-06-13 07:06 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-05-30 11:08 - 2014-06-13 07:06 - 05782528 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-05-30 11:06 - 2014-06-13 07:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-05-30 11:02 - 2014-06-13 07:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-30 10:55 - 2014-06-13 07:06 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-05-30 10:49 - 2014-06-13 07:06 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-05-30 10:46 - 2014-06-13 07:06 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-30 10:44 - 2014-06-13 07:06 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-05-30 10:44 - 2014-06-13 07:06 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-05-30 10:43 - 2014-06-13 07:06 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-05-30 10:42 - 2014-06-13 07:06 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-05-30 10:38 - 2014-06-13 07:06 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-05-30 10:35 - 2014-06-13 07:06 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-05-30 10:34 - 2014-06-13 07:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-05-30 10:33 - 2014-06-13 07:06 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-05-30 10:30 - 2014-06-13 07:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-05-30 10:29 - 2014-06-13 07:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-05-30 10:28 - 2014-06-13 07:06 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-05-30 10:27 - 2014-06-13 07:06 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-05-30 10:24 - 2014-06-13 07:06 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-05-30 10:23 - 2014-06-13 07:06 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-05-30 10:16 - 2014-06-13 07:06 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-05-30 10:10 - 2014-06-13 07:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-05-30 10:06 - 2014-06-13 07:06 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-05-30 10:04 - 2014-06-13 07:06 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-30 10:02 - 2014-06-13 07:06 - 00242688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-05-30 09:56 - 2014-06-13 07:06 - 04244992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-05-30 09:56 - 2014-06-13 07:06 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-05-30 09:54 - 2014-06-13 07:06 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-05-30 09:50 - 2014-06-13 07:06 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-05-30 09:49 - 2014-06-13 07:06 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-05-30 09:43 - 2014-06-13 07:06 - 13522944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-05-30 09:40 - 2014-06-13 07:06 - 11725312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-05-30 09:30 - 2014-06-13 07:06 - 01398272 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-05-30 09:21 - 2014-06-13 07:06 - 01790976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-05-30 09:15 - 2014-06-13 07:06 - 01143296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-05-30 09:13 - 2014-06-13 07:06 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-05-30 09:13 - 2014-06-13 07:06 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-05-29 14:13 - 2013-06-03 19:49 - 00001009 _____ () C:\Users\FM\Desktop\Dropbox.lnk
2014-05-29 14:13 - 2013-06-03 19:47 - 00000000 ____D () C:\Users\FM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
Some content of TEMP:
====================
C:\Users\FM\AppData\Local\Temp\avgnt.exe
C:\Users\FM\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmppmng3v.dll
C:\Users\FM\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\FM\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\FM\AppData\Local\Temp\Quarantine.exe
C:\Users\FM\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\FM\AppData\Local\Temp\SDShelEx-x64.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-06-19 12:59
==================== End Of Log ============================ --- --- ---
--- --- ---
MfG Drops |