Sorry, aber im Uninstallerfeld finde ich kein:
Additional scan Result of Farbar recovery tool.......dort sind nur meine installierten Programme zu sehen und jeweils ohne Zuatz wie Attention!!??
#Malwarebytes Anti-Malware
Malwarebytes | Free Anti-Malware & Internet Security Software
Protection, 11.07.2014 06:54:45, SYSTEM, PAROLE-EMIL-PC, Protection, Malware Protection, Starting,
Protection, 11.07.2014 06:54:45, SYSTEM, PAROLE-EMIL-PC, Protection, Malware Protection, Started,
Protection, 11.07.2014 06:54:45, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Starting,
Protection, 11.07.2014 06:57:54, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Started,
Detection, 11.07.2014 07:25:23, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 85dcf732d593.se, 50896, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 11.07.2014 07:25:25, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 85dcf732d593.se, 50896, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Detection, 11.07.2014 07:25:25, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, IP, 5.150.195.167, 85dcf732d593.se, 50897, Outbound, C:\Program Files (x86)\Google\Chrome\Application\chrome.exe,
Update, 11.07.2014 07:49:53, SYSTEM, PAROLE-EMIL-PC, Scheduler, Malware Database, 2014.7.9.13, 2014.7.11.3,
Protection, 11.07.2014 07:49:56, SYSTEM, PAROLE-EMIL-PC, Protection, Refresh, Starting,
Protection, 11.07.2014 07:49:56, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Stopping,
Protection, 11.07.2014 07:49:57, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Stopped,
Protection, 11.07.2014 07:50:54, SYSTEM, PAROLE-EMIL-PC, Protection, Refresh, Success,
Protection, 11.07.2014 07:50:54, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Starting,
Protection, 11.07.2014 07:51:02, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Started,
Protection, 11.07.2014 11:23:43, SYSTEM, PAROLE-EMIL-PC, Protection, Malware Protection, Starting,
Protection, 11.07.2014 11:23:43, SYSTEM, PAROLE-EMIL-PC, Protection, Malware Protection, Started,
Protection, 11.07.2014 11:23:44, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Starting,
Protection, 11.07.2014 11:25:18, SYSTEM, PAROLE-EMIL-PC, Protection, Malicious Website Protection, Started,
(end)
#AdwCleaner Logfile:
Code:
# AdwCleaner v3.215 - Bericht erstellt am 11/07/2014 um 11:42:04
# Aktualisiert 09/07/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Parole-Emil - PAROLE-EMIL-PC
# Gestartet von : C:\Users\Parole-Emil\Desktop\adwcleaner_3.215.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files (x86)\VNT
Ordner Gelöscht : C:\Program Files\Reimage
Ordner Gelöscht : C:\Users\Parole-Emil\AppData\Local\VNT
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [VNT]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A18D16ED-27B2-4B83-B70C-15E73F099546}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A18D16ED-27B2-4B83-B70C-15E73F099546}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BEE7E029-5037-4DAD-A2DB-82E397AB1A44}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}
Wert Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{2318C2B1-4965-11D4-9B18-009027A5CD4F}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\ClickConnect
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Video-Saver
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17207
-\\ Google Chrome v35.0.1916.153
[ Datei : C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Search Provider] : hxxp://search.conduit.com/Results.aspx?ctid=CT3315513&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP9D0D24B5-7152-4439-A9C1-B3FBBBD58BFB&q={searchTerms}&SSPV=
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
*************************
AdwCleaner[R0].txt - [3381 octets] - [11/07/2014 11:39:16]
AdwCleaner[S0].txt - [3060 octets] - [11/07/2014 11:42:04]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [3120 octets] ##########
--- --- ---
#
#~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x64
Ran by Parole-Emil on 11.07.2014 at 11:51:47,53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] C:\Windows\syswow64\sho7926.tmp
~~~ Folders
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{01B8BC0A-F3B1-4BAD-A91B-39C257B82E43}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{031C83B5-0887-4975-983C-169D4050063C}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{0999AF2C-6866-40AA-9E7A-E22A0EDD18AA}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{0A1BF2E8-E7AD-48EE-B1BD-8C81F4517D5D}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{0A5431CA-A82C-4902-A991-6D8A96B21AE2}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{0E918B3E-A3D1-4564-A218-A958D93DC1FB}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{152D345C-F302-442B-9AFB-4079B9820B78}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{15D61542-BE76-4012-914A-56568950E1B9}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{1DEEF8F6-D492-4668-B227-1CE13DF63BBD}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{1F9ADBC9-06ED-44DF-B56D-2ACBAF5AF88F}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{227C1813-74F8-443A-AB51-473F161B77D5}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{23DCEC08-88A3-4C53-8ED5-19F93321E9DD}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{24B5FDE8-B40D-4850-A5DF-4E74063C9833}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{2A172D16-422C-469E-9F09-DB657E4E0000}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{2A6FB59A-F4FE-461B-ABD3-51CDF18457E5}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{2B107C8B-44F7-4BFA-921E-9E443014777F}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{2B191530-7D31-40FA-8C3D-CC335F2A4AEC}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{2E3600D8-A8AE-4DC1-959A-B2F4CF7DDC2C}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{32914843-FD9C-43DB-BA1E-40B482834CF1}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{36A84EEF-04D2-4BF2-9FCF-3CC22271B0C2}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{37B90329-DF6C-4702-96CC-6EB5DDFB8022}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{38389C57-38C5-4F58-A22D-F981EA8DA8A6}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{39811EFF-AAAC-4BB7-B9F6-10D9DCAA8312}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{3AE02FF0-A8B7-46FA-A95D-CC27854BF3FF}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{3B9A738F-8E92-49A9-A652-7E1690BF9CED}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{3BE4736E-2381-4B54-8D64-4212A233AC8A}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{3CF27409-3483-4FDC-943D-0445379512AC}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{3F804E18-049D-4072-8EDF-2693881844DE}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{3FCF44A6-690C-49B8-94C9-5AE38548C113}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{442FA129-3A33-4798-862D-18501C636C75}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{444053E8-7EA0-4075-9F6B-6C947E004BF9}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{45C4F37A-C9B2-4D58-83DD-40265DA1F6FA}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{48EE38B5-D79C-400F-981E-B54CC2ECC4A4}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{5289EF20-CC5E-4BA9-AD3A-E3E3F3CCD962}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{560A5C46-453F-47F4-9E57-6DF7BDE77B5D}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{5C23D3AA-28F0-4029-8B5C-A9044CA100F5}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{5DDCB7AA-E0B6-4078-8DE2-E7A0F94537B6}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{618C7D62-59D5-4CB7-8FCA-62B73F6EAA82}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{619AD0D9-09BB-49F8-88E0-AB31EE8AB73D}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{620329BF-F49C-44E4-AA9D-9AF27D379B2A}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{632CF15C-197B-4560-A7C4-95201D890ACB}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{64538BF6-99D1-428C-94DE-74BBCD827776}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{648BD098-6357-4495-9A56-9CDB824D260A}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{6492257F-EF21-4017-9DC8-FC65D09EDFE7}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{65AFF2F6-28F6-4E8F-B936-28B30BB433BA}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{67F169A2-DF29-42BD-A6EB-60D969DDD1DE}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{68E5A030-F09D-4502-B27D-5DB70BF91BC0}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{693BD2F1-A198-4716-BED8-DB053367C5DB}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{69CBCCDC-8BC9-44AE-8E63-8CAA304ED264}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{6B3D5E34-97DA-4B28-9828-AAE3E1DE808D}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{6E6AF867-9165-46A5-ABD8-E471BE6767D0}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{6F737177-0A32-4717-A38F-EFD7CBE8F3E0}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{6F9370B1-7A9D-4609-AF82-43D10EC97F33}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{7411EBF6-B1BB-4536-AF07-E309CA72F556}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{743B49D8-CC00-4310-9055-8F5A72E51312}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{7C22936F-AC34-4BD9-B958-F78180661437}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{7D7EB3FA-EEBA-4470-A57D-875943568006}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{7F5B4513-E7AF-4A66-A51F-4D76C2773CDF}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{7F847C83-D37B-4F4B-88BF-976F7F1702D4}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{7FBF5DAA-AB63-4774-B8E2-B18C5920E807}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{8460E816-AA2F-4E10-BCFA-DED0DCDA8D4A}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{858B5BAC-8266-4E42-AE1C-290261E0EED4}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{86CC678F-BB66-4DA1-BE04-98E694841C39}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{8EEE5E5E-3E8C-47DE-AA51-D5E407DCB70E}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{91012547-3BE5-4AA7-B3D0-746F93E4B037}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{940E7244-04B1-4403-99CF-5FC9495EF322}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{971580D3-E334-4842-BFCE-B46DB2C272F5}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{98B7FBA0-DCC6-442F-93B1-26A2D988BFE8}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{998BC3B3-835D-4967-BB58-6FF20568DAA5}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{9B7FCEA3-5CED-4285-9BBC-5C1F4859B890}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{9C31D365-4A13-4F5D-8BCC-81B7F0F8FD50}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{9C846B80-DF5F-48E3-AFCE-47E9638844C4}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{9C8811D5-BDE3-40B0-BF43-77A66AD4A5CC}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{9DB54702-36A5-487A-A7FB-87BD0CA4A657}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{A1BB4583-DAD5-43EB-BBF1-2E472DAC8E35}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{A2A9E9A6-3CFD-4C11-B047-118783B2DC33}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{A48D2EDF-4823-48B3-AF72-FC42003FC0ED}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{AB1677EC-B9DA-43AC-A356-7CDC436DF088}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{ACF8A81B-47DE-4274-9FF4-7A80423B0EB2}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{AD977556-38E4-4B1D-A509-660FCEBB59A2}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{AD9F3358-1204-4999-B3D6-3B9ECDEBC1B0}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{BB7E2EEA-375C-4B20-918D-12A2DD4BC304}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{BCA4D0CD-C205-4E8E-9B49-A64071B18017}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{BE8EA778-FD54-4C20-B5C1-8FDD052E17E3}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{BF43EA6E-4C65-4D53-8510-2D8EC21AE267}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{C2CB2CD4-0B85-4422-B433-0DF0A9564222}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{C54A04D8-DA08-4D3F-A1EA-8F30D205BF08}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{CF2129D4-CE4E-4CED-B887-882AB51D0C98}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{D3F68A33-AED7-4D3B-89A5-A76D26534C34}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{D51AEA15-BE53-4889-9045-74F33CD0493F}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{D7576DF9-AE72-493B-820B-E4B88D78A82D}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{D75AEA55-C65D-4935-B99D-A665F5B08C2A}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{DB070A10-775F-49EF-9353-343CB6EC47A4}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{DE52273E-09D3-4897-A52B-102F68F3253D}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{DFB41D78-8EC5-4714-A9B0-CE74392A206D}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{E6E8DBE4-7919-47C2-BDD8-B814F4250DBA}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{E738DC26-BDD5-4ACC-92DC-7495EC5D1A1F}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{EE3E4F18-40AE-4C13-828B-80E268108176}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{EF8AE837-4A33-4B05-93E2-E68EF43C4C2E}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{F53466D3-7EDF-423C-B425-24E170839C45}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{F6399F5C-8466-4E1D-BB49-F131CC32D742}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{FAA66C18-5A1D-472A-AA7B-28A74B5EF7A8}
Successfully deleted: [Empty Folder] C:\Users\Parole-Emil\appdata\local\{FEBFBA23-2A20-4843-961B-BE5ED84F28EC}
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 11.07.2014 at 12:19:09,63
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
#
#
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-07-2014
Ran by Parole-Emil (administrator) on PAROLE-EMIL-PC on 11-07-2014 12:21:34
Running from C:\Users\Parole-Emil\Desktop
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_WT50RP.EXE
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
() C:\ExpressGateUtil\VAWinService.exe
(ASUS) C:\Windows\AsScrPro.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Sonix Technology Co., Ltd.) C:\Windows\vsnp2uvc.exe
(Marvell Semiconductor, Inc.) C:\Program Files\Hewlett-Packard\PrnStatusMX\PrnStatusMX.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe
() C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe
(syncables, LLC) C:\Program Files (x86)\syncables\syncables desktop\syncables.exe
(BillP Studios) C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\x64\3\E_YATIIUE.EXE
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe
(Clarus, Inc.) C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe
(PixelPlanet GmbH) C:\Program Files (x86)\Common Files\PixelPlanet\PdfPrinter 6\PdfPrinterMonitor.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
() C:\ExpressGateUtil\VAWinAgent.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
() C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVBg] => c:\program files\realtek\audio\hda\ravbg64.exe [2168424 2010-10-13] (Realtek Semiconductor)
HKLM\...\Run: [ETDWare] => C:\Program Files\elantech\etdctrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.)
HKLM\...\Run: [snp2uvc] => c:\windows\vsnp2uvc.exe [909824 2010-01-21] (Sonix Technology Co., Ltd.)
HKLM\...\Run: [PrnStatusMX] => c:\program files\hewlett-packard\prnstatusmx\prnstatusmx.exe [1238528 2007-08-29] (Marvell Semiconductor, Inc.)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "c:\program files\intel\turboboost\runtbgadgetonce.vbs"
HKLM\...\Run: [IntelWireless] => c:\program files\common files\intel\wirelesscommon\ifrmewrk.exe [1931024 2010-07-20] (Intel(R) Corporation)
HKLM\...\Run: [ASUS WebStorage] => c:\program files (x86)\asus\asus webstorage\service\asuswsservice.exe [1754448 2010-03-16] ()
HKLM-x32\...\Run: [UpdatePSTShortCut] => C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe [210216 2010-06-25] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateLBPShortCut] => C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-20] (CyberLink Corp.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [750160 2014-06-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Nuance PDF Reader-reminder] => c:\program files (x86)\nuance\pdf reader\ereg\ereg.exe [328992 2008-11-03] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Microsoft Default Manager] => c:\program files (x86)\microsoft\search enhancement pack\default manager\defmgr.exe [439568 2010-05-11] (Microsoft Corporation)
HKLM-x32\...\Run: [ATKMEDIA] => c:\program files (x86)\asus\atk package\atk media\dmedia.exe [170624 2010-10-08] (ASUS)
HKLM-x32\...\Run: [HControlUser] => c:\program files (x86)\asus\atk package\atk hotkey\hcontroluser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [SonicMasterTray] => c:\program files (x86)\asus\sonicmaster\sonicmastertray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [APSDaemon] => c:\program files (x86)\common files\apple\apple application support\apsdaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [PixelPlanet PdfPrinter-Monitor] => c:\program files (x86)\common files\pixelplanet\pdfprinter 6\pdfprintermonitor.exe [2233912 2011-11-04] (PixelPlanet GmbH)
HKLM-x32\...\Run: [Wireless Console 3] => c:\program files (x86)\asus\wireless console 3\wcourier.exe [1601536 2010-09-24] ()
HKLM-x32\...\Run: [RemoteControl9] => c:\program files (x86)\cyberlink\powerdvd9\pdvd9serv.exe [87336 2009-07-07] (CyberLink Corp.)
HKLM-x32\...\Run: [WSHelperSetup.exe] => c:\program files (x86)\common files\wondershare\wondershare helper compact\wshelper.exe [1985824 2013-07-25] (Wondershare)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => c:\program files (x86)\common files\wondershare\wondershare helper compact\wshelper.exe [1985824 2013-07-25] (Wondershare)
HKLM-x32\...\Run: [VAWinAgent] => c:\expressgateutil\vawinagent.exe [21504 2010-08-13] ()
HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-05-07] (Oracle Corporation)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-26] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2552948775-2487114185-2976450722-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-06] (Acresso Corporation)
HKU\S-1-5-21-2552948775-2487114185-2976450722-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2011-02-27] (Google Inc.)
HKU\S-1-5-21-2552948775-2487114185-2976450722-1000\...\RunOnce: [spchecker] - C:\Program Files (x86)\AVG\AVG10\Notification\SPCheckerTE.exe [390472 2011-07-21] ()
HKU\S-1-5-21-2552948775-2487114185-2976450722-1001\...\Run: [Syncables] => c:\program files (x86)\syncables\syncables desktop\syncables.exe [370480 2010-07-19] (syncables, LLC)
HKU\S-1-5-21-2552948775-2487114185-2976450722-1001\...\Run: [ApplePhotoStreams] => c:\program files (x86)\common files\apple\internet services\applephotostreams.exe [59720 2013-11-20] (Apple Inc.)
HKU\S-1-5-21-2552948775-2487114185-2976450722-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe [496192 2014-02-25] (BillP Studios)
HKU\S-1-5-21-2552948775-2487114185-2976450722-1001\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2552948775-2487114185-2976450722-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21446272 2014-05-08] (Skype Technologies S.A.)
AppInit_DLLs: C:\Windows\System32\nvinitx.dll => C:\Windows\System32\nvinitx.dll [266448 2013-06-21] (NVIDIA Corporation)
AppInit_DLLs-x32: c:\Windows\SysWOW64\nvinit.dll => c:\Windows\SysWOW64\nvinit.dll [214448 2013-06-21] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk
ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Parole-Emil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Guage.lnk
ShortcutTarget: Samsung Auto Backup Guage.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFGuage.exe (Clarus, Inc.)
Startup: C:\Users\Parole-Emil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Real-Time Daemon.lnk
ShortcutTarget: Samsung Auto Backup Real-Time Daemon.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFRealTimeD.exe (Clarus, Inc.)
Startup: C:\Users\Parole-Emil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Auto Backup Scheduler.lnk
ShortcutTarget: Samsung Auto Backup Scheduler.lnk -> C:\Program Files (x86)\Clarus\Samsung Auto Backup\ISFTimerD.exe (Clarus, Inc.)
ShellIconOverlayIdentifiers: 00avast -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
ShellIconOverlayIdentifiers: AsusWSShellExt_B -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)
ShellIconOverlayIdentifiers: AsusWSShellExt_O -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\service\AsusWSShellExt64.dll (eCareme Technologies, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
SearchScopes: HKLM-x32 - DefaultScope value is missing.
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - {268D236D-D64E-41BE-818B-E7348D9049B7} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms}
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
BHO: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
BHO-x32: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Bing Bar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport_x64.dll (APN LLC.)
Toolbar: HKLM-x32 - @C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100 - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-4300-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7C\Passport.dll (APN LLC.)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.60.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpWinExt,version=5.0 - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 - C:\Program Files (x86)\Nuance\PDF Reader\bin\nppdf.dll (Zeon Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM-x32\...\Firefox\Extensions: [msntoolbar@msn.com] - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox
FF Extension: Bing Bar - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011-02-27]
FF HKLM-x32\...\Firefox\Extensions: [{27182e60-b5f3-411c-b545-b44205977502}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension
FF Extension: Search Helper Extension - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension [2011-02-27]
FF HKLM-x32\...\Firefox\Extensions: [{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}] - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension
FF Extension: Default Manager - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension [2011-02-27]
Chrome:
=======
CHR HomePage: hxxp://www.spiegel.de/
CHR StartupUrls: "hxxp://spiegel.de/"
CHR Extension: (Google Docs) - C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-01-31]
CHR Extension: (Google Drive) - C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-01-31]
CHR Extension: (YouTube) - C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-01-31]
CHR Extension: (Google-Suche) - C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-01-31]
CHR Extension: (SiteAdvisor) - C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-01-31]
CHR Extension: (Google Wallet) - C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-19]
CHR Extension: (Google Mail) - C:\Users\Parole-Emil\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-01-31]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2011-04-15]
CHR HKLM-x32\...\Chrome\Extension: [pcoohmdcpejoeggdnihdfhohjgdbllgm] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7C\CRX\ToolbarCR.crx [2013-12-20]
==================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-06-24] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1030224 2014-07-10] (Avira Operations GmbH & Co. KG)
S4 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-12-20] () [File not signed]
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 ezGOSvc; C:\Windows\SysWOW64\ezGOSvc.dll [80256 2011-05-28] ()
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-07-20] ()
R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () [File not signed]
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [77312 2010-08-21] () [File not signed]
S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [X]
S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X]
S2 SZASSIST; "C:\Program Files (x86)\Clarus\Samsung SecretZone\SZAssistSVC.exe" [X]
==================== Drivers (Whitelisted) ====================
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-06-03] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-12-18] (Avira Operations GmbH & Co. KG)
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [81984 2010-10-28] (Fresco Logic)
R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-21] ( )
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-07-11] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800832 2010-09-07] (Sonix Technology Co., Ltd.)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 cpuz134; \??\C:\Users\PAROLE~1\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 mdf16; \??\C:\Program Files (x86)\Clarus\Samsung SecretZone\mdf16.sys [X]
S3 mvd22; \??\C:\Program Files (x86)\Clarus\Samsung SecretZone\mvd22.sys [X]
U3 tmlwf;
U3 tmwfp;
==================== NetSvcs (Whitelisted) ===================
NETSVC: ezGOSvc -> C:\Windows\SysWOW64\ezGOSvc.dll ()
==================== One Month Created Files and Folders ========
2014-07-11 12:21 - 2014-07-11 12:21 - 00000000 ____D () C:\Users\Parole-Emil\Desktop\FRST-OlderVersion
2014-07-11 12:19 - 2014-07-11 12:19 - 00012233 _____ () C:\Users\Parole-Emil\Desktop\JRT.txt
2014-07-11 11:50 - 2014-07-11 11:50 - 01016261 _____ (Thisisu) C:\Users\Parole-Emil\Desktop\JRT.exe
2014-07-11 11:40 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-07-11 11:39 - 2014-07-11 11:42 - 00000000 ____D () C:\AdwCleaner
2014-07-11 11:37 - 2014-07-11 11:38 - 01348263 _____ () C:\Users\Parole-Emil\Desktop\adwcleaner_3.215.exe
2014-07-11 11:34 - 2014-07-11 11:34 - 00002277 _____ () C:\Users\Parole-Emil\Desktop\mbam.txt
2014-07-11 10:34 - 2014-07-11 10:34 - 00001270 _____ () C:\Users\Parole-Emil\Desktop\Revo Uninstaller.lnk
2014-07-11 10:32 - 2014-07-11 10:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Parole-Emil\Downloads\revosetup95.exe
2014-07-11 06:54 - 2014-07-11 06:54 - 01052624 _____ () C:\Windows\Minidump\071114-37643-01.dmp
2014-07-11 06:54 - 2014-07-11 06:54 - 00000000 ____D () C:\Windows\Minidump
2014-07-11 06:53 - 2014-07-11 06:53 - 583584954 _____ () C:\Windows\MEMORY.DMP
2014-07-10 12:11 - 2014-07-10 12:14 - 00039102 _____ () C:\Users\Parole-Emil\Desktop\Addition.txt
2014-07-10 12:09 - 2014-07-11 12:21 - 00026708 _____ () C:\Users\Parole-Emil\Desktop\FRST.txt
2014-07-10 12:08 - 2014-07-11 12:21 - 00000000 ____D () C:\FRST
2014-07-10 12:07 - 2014-07-11 12:21 - 02084864 _____ (Farbar) C:\Users\Parole-Emil\Desktop\FRST64.exe
2014-07-10 07:31 - 2014-07-10 07:32 - 34403281 _____ () C:\Users\Parole-Emil\Downloads\MW-64-sample.wmv
2014-07-10 06:59 - 2014-06-18 04:18 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-07-10 06:59 - 2014-06-18 03:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-07-10 06:59 - 2014-06-18 03:10 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-07-10 06:58 - 2014-06-20 22:14 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-10 06:58 - 2014-06-19 03:06 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-07-10 06:58 - 2014-06-19 02:41 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-07-10 06:58 - 2014-06-19 02:31 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-07-10 06:58 - 2014-06-19 02:16 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-10 06:58 - 2014-06-19 01:59 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-10 06:58 - 2014-06-19 01:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-10 06:58 - 2014-06-19 01:37 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-10 06:58 - 2014-06-19 01:36 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-10 06:58 - 2014-06-19 01:28 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-10 06:58 - 2014-06-19 01:22 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-10 06:58 - 2014-06-19 01:12 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-10 06:58 - 2014-06-19 01:06 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-10 06:58 - 2014-06-19 00:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-10 06:58 - 2014-06-19 00:49 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-10 06:58 - 2014-06-19 00:45 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-10 06:58 - 2014-06-19 00:34 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-10 06:58 - 2014-06-19 00:09 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-10 06:57 - 2014-06-20 21:39 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-10 06:57 - 2014-06-19 03:39 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-10 06:57 - 2014-06-19 03:06 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-07-10 06:57 - 2014-06-19 02:48 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-10 06:57 - 2014-06-19 02:42 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-10 06:57 - 2014-06-19 02:42 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-07-10 06:57 - 2014-06-19 02:41 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-10 06:57 - 2014-06-19 02:32 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-07-10 06:57 - 2014-06-19 02:26 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-07-10 06:57 - 2014-06-19 02:24 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-07-10 06:57 - 2014-06-19 02:24 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-07-10 06:57 - 2014-06-19 02:23 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-10 06:57 - 2014-06-19 02:14 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-07-10 06:57 - 2014-06-19 02:09 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-10 06:57 - 2014-06-19 01:53 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-07-10 06:57 - 2014-06-19 01:51 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-10 06:57 - 2014-06-19 01:50 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-10 06:57 - 2014-06-19 01:48 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-10 06:57 - 2014-06-19 01:39 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-10 06:57 - 2014-06-19 01:38 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-10 06:57 - 2014-06-19 01:35 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-10 06:57 - 2014-06-19 01:33 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-10 06:57 - 2014-06-19 01:32 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-10 06:57 - 2014-06-19 01:28 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-10 06:57 - 2014-06-19 01:27 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-10 06:57 - 2014-06-19 01:27 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-07-10 06:57 - 2014-06-19 01:25 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-10 06:57 - 2014-06-19 01:23 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-10 06:57 - 2014-06-19 01:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-10 06:57 - 2014-06-19 00:58 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-10 06:57 - 2014-06-19 00:58 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-10 06:57 - 2014-06-19 00:52 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-10 06:57 - 2014-06-19 00:51 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-10 06:57 - 2014-06-19 00:46 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-10 06:57 - 2014-06-19 00:35 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-10 06:57 - 2014-06-19 00:15 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-10 06:57 - 2014-06-19 00:13 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-10 06:57 - 2014-06-19 00:07 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-10 06:56 - 2014-06-05 16:45 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-07-10 06:56 - 2014-06-05 16:26 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2014-07-10 06:56 - 2014-06-05 16:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-07-09 12:52 - 2014-07-09 13:52 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-08 12:10 - 2014-07-08 12:10 - 00000000 _____ () C:\Users\Parole-Emil\AppData\Local\{E0C66807-1EF3-4F20-909D-478BE4C922C4}
2014-07-08 11:34 - 2014-07-11 11:50 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-08 11:34 - 2014-07-08 11:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-08 11:34 - 2014-07-08 11:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-08 11:34 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-07-08 11:34 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-07-05 07:34 - 2014-07-11 11:40 - 00013296 _____ () C:\Windows\system32\ScanResults.xml
2014-07-05 07:29 - 2014-07-11 11:32 - 00007312 _____ () C:\Windows\system32\SettingsFile
2014-07-05 07:29 - 2014-07-11 11:32 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2014-07-04 21:00 - 2014-07-04 21:00 - 00000000 ____D () C:\Users\Parole-Emil\AppData\Local\Skype
2014-07-04 20:59 - 2014-07-04 20:59 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-07-04 20:59 - 2014-07-04 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-07-01 11:22 - 2014-07-01 11:22 - 00000000 __SHD () C:\Users\Parole-Emil\AppData\Local\EmieUserList
2014-07-01 11:22 - 2014-07-01 11:22 - 00000000 __SHD () C:\Users\Parole-Emil\AppData\Local\EmieSiteList
2014-07-01 11:11 - 2014-07-01 11:11 - 00004298 _____ () C:\Windows\System32\Tasks\ReimageUpdater
2014-07-01 11:11 - 2014-07-01 11:11 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-01 11:09 - 2014-07-11 11:31 - 00000163 _____ () C:\Windows\Reimage.ini
2014-07-01 00:36 - 2014-07-01 00:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-07-01 00:35 - 2011-03-14 03:03 - 00083968 _____ (SEIKO EPSON CORPORATION) C:\Windows\system32\E_YD4BIUE.DLL
2014-07-01 00:35 - 2007-04-10 01:06 - 00010752 _____ (SEIKO EPSON CORP.) C:\Windows\system32\E_GCINST.DLL
2014-06-18 18:51 - 2014-06-18 18:51 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-06-18 18:51 - 2014-06-18 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-18 18:49 - 2014-06-18 18:51 - 00000000 ____D () C:\Program Files\iTunes
2014-06-18 18:49 - 2014-06-18 18:51 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-18 18:49 - 2014-06-18 18:49 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-06-18 18:45 - 2014-06-18 18:45 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-06-18 18:45 - 2014-06-18 18:45 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-06-18 18:45 - 2014-06-18 18:45 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-06-18 18:44 - 2014-06-18 18:44 - 00000000 ____D () C:\Program Files\Bonjour
2014-06-18 18:44 - 2014-06-18 18:44 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-06-18 18:33 - 2014-06-18 18:34 - 112616784 _____ (Apple Inc.) C:\Users\Parole-Emil\Downloads\iTunes64Setup.exe
2014-06-18 17:12 - 2014-06-18 17:12 - 00895120 _____ (Google Inc.) C:\Users\Parole-Emil\Downloads\ChromeSetup.exe
2014-06-18 16:50 - 2014-06-18 18:49 - 00000000 ____D () C:\Program Files\iPod
2014-06-12 05:57 - 2014-06-12 05:59 - 00000826 _____ () C:\Windows\SecuniaPackage.log
2014-06-11 17:41 - 2014-05-08 11:32 - 03178496 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-06-11 17:41 - 2014-05-08 11:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-06-11 17:41 - 2014-04-25 04:34 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-06-11 17:41 - 2014-04-25 04:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2014-06-11 17:41 - 2014-04-05 04:47 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-06-11 17:41 - 2014-04-05 04:47 - 00288192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-06-11 17:41 - 2014-03-26 16:44 - 02002432 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-06-11 17:41 - 2014-03-26 16:44 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-06-11 17:41 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-06-11 17:41 - 2014-03-26 16:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-06-11 17:41 - 2014-03-26 16:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2014-06-11 17:41 - 2014-03-26 16:27 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-06-11 17:41 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2014-06-11 17:41 - 2014-03-26 16:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-06-11 17:39 - 2014-06-08 11:13 - 00506368 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-06-11 17:39 - 2014-06-08 11:08 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
==================== One Month Modified Files and Folders =======
2014-07-11 12:22 - 2014-07-10 12:09 - 00026708 _____ () C:\Users\Parole-Emil\Desktop\FRST.txt
2014-07-11 12:21 - 2014-07-11 12:21 - 00000000 ____D () C:\Users\Parole-Emil\Desktop\FRST-OlderVersion
2014-07-11 12:21 - 2014-07-10 12:08 - 00000000 ____D () C:\FRST
2014-07-11 12:21 - 2014-07-10 12:07 - 02084864 _____ (Farbar) C:\Users\Parole-Emil\Desktop\FRST64.exe
2014-07-11 12:19 - 2014-07-11 12:19 - 00012233 _____ () C:\Users\Parole-Emil\Desktop\JRT.txt
2014-07-11 12:18 - 2011-10-29 14:50 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-07-11 11:56 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-07-11 11:56 - 2009-07-14 06:45 - 00010240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-07-11 11:54 - 2011-02-27 07:07 - 01800803 _____ () C:\Windows\WindowsUpdate.log
2014-07-11 11:52 - 2012-03-30 11:05 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-07-11 11:50 - 2014-07-11 11:50 - 01016261 _____ (Thisisu) C:\Users\Parole-Emil\Desktop\JRT.exe
2014-07-11 11:50 - 2014-07-08 11:34 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-07-11 11:45 - 2011-10-29 14:50 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-07-11 11:44 - 2011-02-27 07:46 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-11 11:44 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-07-11 11:44 - 2009-07-14 06:51 - 00113976 _____ () C:\Windows\setupact.log
2014-07-11 11:43 - 2011-02-27 07:41 - 00953378 _____ () C:\Windows\PFRO.log
2014-07-11 11:42 - 2014-07-11 11:39 - 00000000 ____D () C:\AdwCleaner
2014-07-11 11:40 - 2014-07-05 07:34 - 00013296 _____ () C:\Windows\system32\ScanResults.xml
2014-07-11 11:38 - 2014-07-11 11:37 - 01348263 _____ () C:\Users\Parole-Emil\Desktop\adwcleaner_3.215.exe
2014-07-11 11:34 - 2014-07-11 11:34 - 00002277 _____ () C:\Users\Parole-Emil\Desktop\mbam.txt
2014-07-11 11:32 - 2014-07-05 07:29 - 00007312 _____ () C:\Windows\system32\SettingsFile
2014-07-11 11:32 - 2014-07-05 07:29 - 00000464 _____ () C:\Windows\system32\ScannerSettings
2014-07-11 11:31 - 2014-07-01 11:09 - 00000163 _____ () C:\Windows\Reimage.ini
2014-07-11 11:23 - 2009-07-14 06:45 - 00322056 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-07-11 11:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-07-11 11:19 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-07-11 10:34 - 2014-07-11 10:34 - 00001270 _____ () C:\Users\Parole-Emil\Desktop\Revo Uninstaller.lnk
2014-07-11 10:34 - 2014-01-29 18:48 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-07-11 10:32 - 2014-07-11 10:32 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Parole-Emil\Downloads\revosetup95.exe
2014-07-11 07:23 - 2013-08-15 18:38 - 00000000 ____D () C:\Windows\system32\MRT
2014-07-11 07:14 - 2011-05-21 09:56 - 96441528 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-07-11 07:01 - 2009-07-14 07:32 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-07-11 07:00 - 2011-05-21 21:14 - 00000000 ____D () C:\Users\Parole-Emil\AppData\Roaming\Skype
2014-07-11 06:54 - 2014-07-11 06:54 - 01052624 _____ () C:\Windows\Minidump\071114-37643-01.dmp
2014-07-11 06:54 - 2014-07-11 06:54 - 00000000 ____D () C:\Windows\Minidump
2014-07-11 06:53 - 2014-07-11 06:53 - 583584954 _____ () C:\Windows\MEMORY.DMP
2014-07-10 12:28 - 2014-02-21 19:31 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2014-07-10 12:14 - 2014-07-10 12:11 - 00039102 _____ () C:\Users\Parole-Emil\Desktop\Addition.txt
2014-07-10 07:42 - 2012-03-10 13:02 - 01250816 ___SH () C:\Users\Parole-Emil\Downloads\Thumbs.db
2014-07-10 07:32 - 2014-07-10 07:31 - 34403281 _____ () C:\Users\Parole-Emil\Downloads\MW-64-sample.wmv
2014-07-10 06:28 - 2014-01-22 20:57 - 00000296 _____ () C:\Windows\Tasks\DLL-Files FixerASKUSER.job
2014-07-09 13:52 - 2014-07-09 12:52 - 05659136 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerInstaller.exe
2014-07-09 13:52 - 2012-03-30 11:05 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-07-09 13:52 - 2012-03-30 11:04 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-09 13:52 - 2011-06-13 17:58 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-08 12:10 - 2014-07-08 12:10 - 00000000 _____ () C:\Users\Parole-Emil\AppData\Local\{E0C66807-1EF3-4F20-909D-478BE4C922C4}
2014-07-08 11:34 - 2014-07-08 11:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-07-08 11:34 - 2014-07-08 11:34 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-07-08 11:34 - 2014-03-12 11:11 - 00001108 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-07-08 11:34 - 2014-03-12 11:11 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-07-08 11:34 - 2014-01-30 20:14 - 00000000 ____D () C:\Users\Parole-Emil\AppData\Roaming\Malwarebytes
2014-07-08 11:34 - 2014-01-30 20:14 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-07-06 15:41 - 2009-08-04 11:51 - 00700134 _____ () C:\Windows\system32\perfh007.dat
2014-07-06 15:41 - 2009-08-04 11:51 - 00149984 _____ () C:\Windows\system32\perfc007.dat
2014-07-06 15:41 - 2009-07-14 07:13 - 01622300 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-07-04 21:00 - 2014-07-04 21:00 - 00000000 ____D () C:\Users\Parole-Emil\AppData\Local\Skype
2014-07-04 20:59 - 2014-07-04 20:59 - 00002517 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-07-04 20:59 - 2014-07-04 20:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-07-04 20:59 - 2011-05-21 21:13 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-07-04 20:59 - 2011-05-21 21:13 - 00000000 ____D () C:\ProgramData\Skype
2014-07-04 06:26 - 2011-02-27 07:59 - 00002362 _____ () C:\Windows\system32\ServiceFilter.ini
2014-07-04 06:26 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-01 11:22 - 2014-07-01 11:22 - 00000000 __SHD () C:\Users\Parole-Emil\AppData\Local\EmieUserList
2014-07-01 11:22 - 2014-07-01 11:22 - 00000000 __SHD () C:\Users\Parole-Emil\AppData\Local\EmieSiteList
2014-07-01 11:11 - 2014-07-01 11:11 - 00004298 _____ () C:\Windows\System32\Tasks\ReimageUpdater
2014-07-01 11:11 - 2014-07-01 11:11 - 00000000 ____D () C:\ProgramData\Reimage Protector
2014-07-01 00:36 - 2014-07-01 00:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2014-07-01 00:06 - 2014-01-31 13:34 - 00000000 ____D () C:\ProgramData\EPSON
2014-07-01 00:04 - 2014-01-31 13:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
2014-07-01 00:04 - 2014-01-31 13:36 - 00000000 ____D () C:\Program Files (x86)\Epson Software
2014-06-27 11:14 - 2011-08-22 19:20 - 00000000 ____D () C:\Users\Parole-Emil\Documents\XEN
2014-06-24 11:57 - 2014-01-22 10:06 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-06-20 22:14 - 2014-07-10 06:58 - 00266424 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-06-20 21:39 - 2014-07-10 06:57 - 00240824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-06-19 03:39 - 2014-07-10 06:57 - 23464448 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-06-19 03:06 - 2014-07-10 06:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-06-19 03:06 - 2014-07-10 06:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-06-19 02:48 - 2014-07-10 06:57 - 02768384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-06-19 02:42 - 2014-07-10 06:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-06-19 02:42 - 2014-07-10 06:57 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-06-19 02:41 - 2014-07-10 06:58 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-06-19 02:41 - 2014-07-10 06:57 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-06-19 02:32 - 2014-07-10 06:57 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-06-19 02:31 - 2014-07-10 06:58 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-06-19 02:26 - 2014-07-10 06:57 - 00598016 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-06-19 02:24 - 2014-07-10 06:57 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-06-19 02:24 - 2014-07-10 06:57 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-06-19 02:23 - 2014-07-10 06:57 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-06-19 02:16 - 2014-07-10 06:58 - 17276416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-06-19 02:14 - 2014-07-10 06:57 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-06-19 02:09 - 2014-07-10 06:57 - 00452608 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-06-19 01:59 - 2014-07-10 06:58 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-06-19 01:56 - 2014-07-10 06:58 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-06-19 01:53 - 2014-07-10 06:57 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-06-19 01:51 - 2014-07-10 06:57 - 05721088 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-06-19 01:50 - 2014-07-10 06:57 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-06-19 01:48 - 2014-07-10 06:57 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-06-19 01:39 - 2014-07-10 06:57 - 00608768 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-06-19 01:38 - 2014-07-10 06:57 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-06-19 01:37 - 2014-07-10 06:58 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-06-19 01:36 - 2014-07-10 06:58 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-06-19 01:35 - 2014-07-10 06:57 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-06-19 01:33 - 2014-07-10 06:57 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-06-19 01:32 - 2014-07-10 06:57 - 02179072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-06-19 01:28 - 2014-07-10 06:58 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-06-19 01:28 - 2014-07-10 06:57 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-06-19 01:27 - 2014-07-10 06:57 - 02040832 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-06-19 01:27 - 2014-07-10 06:57 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-06-19 01:25 - 2014-07-10 06:57 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-06-19 01:23 - 2014-07-10 06:57 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-06-19 01:22 - 2014-07-10 06:58 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-06-19 01:12 - 2014-07-10 06:58 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-06-19 01:06 - 2014-07-10 06:58 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-06-19 01:01 - 2014-07-10 06:57 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-06-19 00:59 - 2014-07-10 06:58 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-06-19 00:58 - 2014-07-10 06:57 - 02266112 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-06-19 00:58 - 2014-07-10 06:57 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-06-19 00:52 - 2014-07-10 06:57 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-06-19 00:51 - 2014-07-10 06:57 - 13527040 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-06-19 00:49 - 2014-07-10 06:58 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-06-19 00:46 - 2014-07-10 06:57 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-06-19 00:45 - 2014-07-10 06:58 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-06-19 00:35 - 2014-07-10 06:57 - 11742208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-06-19 00:34 - 2014-07-10 06:58 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-06-19 00:15 - 2014-07-10 06:57 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-06-19 00:13 - 2014-07-10 06:57 - 01791488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-06-19 00:09 - 2014-07-10 06:58 - 01139200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-06-19 00:07 - 2014-07-10 06:57 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-06-18 22:35 - 2013-12-29 05:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-06-18 22:35 - 2011-02-27 08:04 - 00000000 ____D () C:\ExpressGateUtil
2014-06-18 22:35 - 2011-02-27 07:56 - 00000000 ____D () C:\ProgramData\P4G
2014-06-18 22:35 - 2009-07-14 09:44 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-06-18 22:35 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-06-18 18:51 - 2014-06-18 18:51 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-06-18 18:51 - 2014-06-18 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-06-18 18:51 - 2014-06-18 18:49 - 00000000 ____D () C:\Program Files\iTunes
2014-06-18 18:51 - 2014-06-18 18:49 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-06-18 18:51 - 2013-11-07 08:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-06-18 18:49 - 2014-06-18 18:49 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-06-18 18:49 - 2014-06-18 16:50 - 00000000 ____D () C:\Program Files\iPod
2014-06-18 18:45 - 2014-06-18 18:45 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-06-18 18:45 - 2014-06-18 18:45 - 00000000 ____D () C:\Windows\System32\Tasks\Apple
2014-06-18 18:45 - 2014-06-18 18:45 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2014-06-18 18:44 - 2014-06-18 18:44 - 00000000 ____D () C:\Program Files\Bonjour
2014-06-18 18:44 - 2014-06-18 18:44 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2014-06-18 18:44 - 2014-05-28 17:35 - 00000000 ____D () C:\ProgramData\Apple
2014-06-18 18:34 - 2014-06-18 18:33 - 112616784 _____ (Apple Inc.) C:\Users\Parole-Emil\Downloads\iTunes64Setup.exe
2014-06-18 18:28 - 2011-11-20 17:52 - 00000000 ____D () C:\Program Files (x86)\Safari
2014-06-18 18:27 - 2013-06-03 13:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2014-06-18 18:27 - 2013-06-03 13:25 - 00000000 ____D () C:\Program Files (x86)\QuickTime
2014-06-18 17:14 - 2013-12-29 05:38 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-06-18 17:13 - 2011-10-29 14:50 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-06-18 17:13 - 2011-10-29 14:50 - 00003854 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-06-18 17:12 - 2014-06-18 17:12 - 00895120 _____ (Google Inc.) C:\Users\Parole-Emil\Downloads\ChromeSetup.exe
2014-06-18 13:04 - 2014-01-31 13:35 - 00000000 ____D () C:\Users\Parole-Emil\Desktop\EPSON Scan
2014-06-18 12:59 - 2014-01-31 13:37 - 00000000 ____D () C:\Users\Parole-Emil\AppData\Roaming\Epson
2014-06-18 12:38 - 2011-05-18 22:20 - 00000000 ____D () C:\Users\Parole-Emil
2014-06-18 04:18 - 2014-07-10 06:59 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-06-18 03:51 - 2014-07-10 06:59 - 00646144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\osk.exe
2014-06-18 03:10 - 2014-07-10 06:59 - 03157504 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-06-12 05:59 - 2014-06-12 05:57 - 00000826 _____ () C:\Windows\SecuniaPackage.log
2014-06-12 05:30 - 2011-05-28 11:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-06-12 05:25 - 2014-05-01 21:51 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-06-11 10:44 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF
Some content of TEMP:
====================
C:\Users\Parole-Emil\AppData\Local\Temp\avgnt.exe
C:\Users\Parole-Emil\AppData\Local\Temp\cm_setup.exe
C:\Users\Parole-Emil\AppData\Local\Temp\Quarantine.exe
C:\Users\Parole-Emil\AppData\Local\Temp\ReimagePackage.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-09 02:11
==================== End Of Log ============================
--- --- ---
--- --- ---