Sorry, ich dachte, dass Punkt 3 der Regeln zur Eröffnung eines neuen Themas hier zutreffen würde.
FRST.txt:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-08-2014 01
Ran by *********** (administrator) on LAPTOP on 20-08-2014 12:17:54
Running from C:\Users\***********\Desktop
Platform: Windows 8.1 Pro (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_70dacb64382a61a7\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Cisco Systems, Inc.) C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Andrea Electronics Corporation) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_70dacb64382a61a7\AESTSr64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corp.) C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
() C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
(Lupinho.Net) C:\Program Files\Lupinho.Net\HardlinkBackup\HardlinkBackup.Service.exe
() C:\Program Files\ShrewSoft\VPN Client\iked.exe
() C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psia.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\vmms.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\sua.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.24.15\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20573_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(hxxp://tortoisesvn.net) C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
() C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(TrueCrypt Foundation) C:\Program Files\TrueCrypt\TrueCrypt.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
( Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
(Dropbox, Inc.) C:\Users\***********\AppData\Roaming\Dropbox\bin\Dropbox.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-14] (Synaptics Incorporated)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [487424 2010-03-23] (IDT, Inc.)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-11-14] (NVIDIA Corporation)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM-x32\...\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [323640 2009-11-24] ( Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] => C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe [707984 2013-10-10] (Cisco Systems, Inc.)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [468112 2011-07-25] (CANON INC.)
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637528 2012-10-09] (CANON INC.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [PDFPrint] => C:\Program Files (x86)\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-08-08] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [224128 2014-06-16] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [Rainlendar2] => C:\Program Files (x86)\Rainlendar2\Rainlendar2.exe [2598496 2013-03-10] ()
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22734160 2014-08-08] (Google)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [TrueCrypt] => C:\Program Files\TrueCrypt\TrueCrypt.exe [1516496 2013-12-23] (TrueCrypt Foundation)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [Spotify Web Helper] => C:\Users\***********\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-07-19] (Spotify Ltd)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [784392 2014-05-29] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [GoogleChromeAutoLaunch_6EC6A5E07D40E919B614D70E465AAA4A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [860488 2014-08-07] (Google Inc.)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [Boxcryptor.exe] => C:\Program Files (x86)\Boxcryptor\Boxcryptor.exe [1063680 2014-07-11] (Secomba GmbH)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [466656 2014-05-23] (Sony)
HKU\S-1-5-21-22145797-4037712363-3399924978-1001\...\MountPoints2: {02f12018-98c0-11e3-825f-c80aa96dcdf0} - "F:\Startme.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\aiStarter.lnk
ShortcutTarget: aiStarter.lnk -> C:\Program Files (x86)\AppInventor\aiStarter.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HardlinkBackup Tray.lnk
ShortcutTarget: HardlinkBackup Tray.lnk -> C:\Program Files\Lupinho.Net\HardlinkBackup\HardlinkBackupTray.exe (Lupinho.Net)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\***********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
Startup: C:\Users\***********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled ()
Startup: C:\Users\***********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\***********\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
SSODL: EldosMountNotificator-cbfs4 - {D9E5D311-6E59-493B-AD6F-DA8260A95CEE} - C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
SSODL-x32: EldosMountNotificator-cbfs4 - {D9E5D311-6E59-493B-AD6F-DA8260A95CEE} - C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\***********\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\***********\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\***********\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: DropboxExt4 -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\***********\AppData\Roaming\Dropbox\bin\DropboxExt64.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: EldosIconOverlay-cbfs4 -> {9737C1F0-9DC5-4F74-825F-E00C3F61A56B} => C:\Windows\system32\cbfsMntNtf4.dll (EldoS Corporation)
ShellIconOverlayIdentifiers: GDriveBlacklistedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedEditOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSharedViewOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers: GDriveSyncingOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll (Google)
ShellIconOverlayIdentifiers-x32: 1TortoiseNormal -> {C5994560-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 2TortoiseModified -> {C5994561-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 3TortoiseConflict -> {C5994562-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 4TortoiseLocked -> {C5994563-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 5TortoiseReadOnly -> {C5994564-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 6TortoiseDeleted -> {C5994565-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 7TortoiseAdded -> {C5994566-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 8TortoiseIgnored -> {C5994567-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: 9TortoiseUnversioned -> {C5994568-53D9-4125-87C9-F193FC689CB2} => C:\Program Files (x86)\Common Files\TortoiseOverlays\TortoiseOverlays.dll (hxxp://tortoisesvn.net)
ShellIconOverlayIdentifiers-x32: DropboxExt1 -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\***********\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt2 -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\***********\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: DropboxExt3 -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\***********\AppData\Roaming\Dropbox\bin\DropboxExt.24.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: EldosIconOverlay-cbfs4 -> {9737C1F0-9DC5-4F74-825F-E00C3F61A56B} => C:\Windows\SysWOW64\cbfsMntNtf4.dll (EldoS Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x63110755E619CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM - DefaultScope {B75953C5-6F1F-48A1-8683-86923F952B83} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKLM - {B75953C5-6F1F-48A1-8683-86923F952B83} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - DefaultScope {B75953C5-6F1F-48A1-8683-86923F952B83} URL = hxxp://www.sm.de/?q={searchTerms}
SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
SearchScopes: HKCU - {B75953C5-6F1F-48A1-8683-86923F952B83} URL = hxxp://www.sm.de/?q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre8\bin\ssv.dll (Oracle Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll (Logitech, Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre8\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default
FF DefaultSearchEngine: SuchMaschine
FF SearchEngineOrder.1: SuchMaschine
FF SelectedSearchEngine: SuchMaschine
FF Homepage: about:home
FF Keyword.URL: hxxp://www.google.de/search?q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_179.dll ()
FF Plugin: @java.com/DTPlugin,version=11.11.2 -> C:\Program Files\Java\jre8\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.11.2 -> C:\Program Files\Java\jre8\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_179.dll ()
FF Plugin-x32: @esn/npbattlelog,version=2.4.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.4.0\npbattlelog.dll (EA Digital Illusions CE AB)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.65.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\searchplugins\avira-safesearch.xml
FF SearchPlugin: C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\searchplugins\search_engine.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Avira Browser Safety - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\abs@avira.com [2014-08-19]
FF Extension: German Dictionary - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\de-DE@dictionaries.addons.mozilla.org [2014-06-10]
FF Extension: United States English Spellchecker - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\en-US@dictionaries.addons.mozilla.org [2013-12-24]
FF Extension: Pocket - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\isreaditlater@ideashower.com [2014-07-02]
FF Extension: WOT - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2013-12-22]
FF Extension: DownloadHelper - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-08-08]
FF Extension: Evernote Web Clipper - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800} [2013-12-22]
FF Extension: SearchPreview - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{EF522540-89F5-46b9-B6FE-1829E2B572C6} [2014-05-22]
FF Extension: Adblock Plus Pop-up Addon - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\adblockpopups@jessehakanen.net.xpi [2013-12-22]
FF Extension: facepaste - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\facepaste.firefox.addon@azabani.com.xpi [2013-12-22]
FF Extension: Grooveshark Unlocker - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\groovesharkUnlocker@overlord1337.xpi [2013-12-22]
FF Extension: Deutsch (DE) Language Pack - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\langpack-de@firefox.mozilla.org.xpi [2013-12-24]
FF Extension: Lazarus: Form Recovery - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\lazarus@interclue.com.xpi [2013-12-22]
FF Extension: Save Images - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\LDSI_plashcor@gmail.com.xpi [2013-12-22]
FF Extension: FlashGot - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2013-12-22]
FF Extension: Image Zoom - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}.xpi [2013-12-22]
FF Extension: NoScript - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2013-12-22]
FF Extension: Procon Latte Content Filter - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{9D6218B8-03C7-4b91-AA43-680B305DD35C}.xpi [2013-12-22]
FF Extension: Adblock Plus - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-22]
FF Extension: BetterPrivacy - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2013-12-22]
FF Extension: Download Statusbar - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi [2013-12-22]
FF Extension: Greasemonkey - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2013-12-22]
FF Extension: User Agent Switcher - C:\Users\***********\AppData\Roaming\Mozilla\Firefox\Profiles\7665o0nt.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2013-12-22]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2014-06-04]
Chrome:
=======
CHR Extension: (Google Docs) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-03-25]
CHR Extension: (Google Drive) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-03-25]
CHR Extension: (YouTube) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-03-25]
CHR Extension: (Google-Suche) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-03-25]
CHR Extension: (AdBlock) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-03-25]
CHR Extension: (Adblock Advisor) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplojogpbcbnjoemcalepfmbcpnkpjjo [2014-03-25]
CHR Extension: (Video Grabber) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\keinlcafjoaeegnnbmokjfbkkgfmpljh [2014-03-25]
CHR Extension: (Google Wallet) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-03-25]
CHR Extension: (Google Mail) - C:\Users\***********\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-03-25]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AESTFilters; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_70dacb64382a61a7\AESTSr64.exe [89600 2009-03-03] (Andrea Electronics Corporation)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-08-08] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-08-08] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG)
R2 BingDesktopUpdate; C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktopUpdater.exe [173272 2013-11-01] (Microsoft Corp.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2356912 2014-07-19] (Microsoft Corporation)
R2 DirMngr; C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe [218112 2013-10-07] () [File not signed]
S3 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [639488 2014-08-03] (FileZilla Project) [File not signed]
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
R2 HardlinkBackupService; C:\Program Files\Lupinho.Net\HardlinkBackup\HardlinkBackup.Service.exe [15360 2014-04-02] (Lupinho.Net) [File not signed]
R2 iked; C:\Program Files\ShrewSoft\VPN Client\iked.exe [1127736 2013-07-01] ()
R2 ipsecd; C:\Program Files\ShrewSoft\VPN Client\ipsecd.exe [810808 2013-07-01] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1494304 2013-12-10] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15125280 2013-11-14] (NVIDIA Corporation)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [174088 2014-05-29] (Sandboxie Holdings, LLC)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
R2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_70dacb64382a61a7\STacSV64.exe [247808 2010-03-23] (IDT, Inc.)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
R2 vmms; C:\Windows\system32\vmms.exe [13401600 2014-05-10] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-02-25] (Avira Operations GmbH & Co. KG)
S3 BthA2DP; C:\Windows\system32\drivers\BthA2DP.sys [131584 2013-08-22] (Microsoft Corporation)
R1 cbfs4; C:\Windows\system32\drivers\cbfs4.sys [387776 2013-11-15] (EldoS Corporation)
R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [68960 2014-02-09] (Microsoft Corporation)
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [19456 2014-02-09] (Microsoft Corporation)
R3 NdisImPlatformMp; C:\Windows\system32\DRIVERS\NdisImPlatform.sys [124928 2013-08-22] (Microsoft Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [39200 2013-11-14] (NVIDIA Corporation)
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [22016 2014-02-09] (Microsoft Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-12-06] (Secunia)
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [27136 2014-02-07] (Microsoft Corporation)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [185352 2014-05-29] (Sandboxie Holdings, LLC)
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] ()
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [18944 2014-01-27] (Microsoft Corporation)
R3 VMSMP; C:\Windows\system32\DRIVERS\vmswitch.sys [691200 2014-05-27] (Microsoft Corporation)
S3 VMSP; C:\Windows\system32\DRIVERS\vmswitch.sys [691200 2014-05-27] (Microsoft Corporation)
S3 VMSVSF; C:\Windows\system32\DRIVERS\vmswitch.sys [691200 2014-05-27] (Microsoft Corporation)
S3 VMSVSP; C:\Windows\system32\DRIVERS\vmswitch.sys [691200 2014-05-27] (Microsoft Corporation)
R3 vpnpbus; C:\Windows\System32\drivers\vpnpbus.sys [18624 2013-11-15] (EldoS Corporation)
S3 vpnva; C:\Windows\system32\DRIVERS\vpnva64-6.sys [52080 2013-10-10] (Cisco Systems, Inc.)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-26] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
R3 WUDFWpdComp; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 YMIDUSBW; C:\Windows\system32\drivers\ymidusbx64.sys [51496 2013-04-04] (Yamaha Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-20 12:17 - 2014-08-20 12:18 - 00034390 _____ () C:\Users\***********\Desktop\FRST.txt
2014-08-20 12:17 - 2014-08-20 12:18 - 00000000 ____D () C:\FRST
2014-08-20 12:17 - 2014-08-20 12:17 - 00028261 _____ () C:\Users\***********\Downloads\FRST.txt
2014-08-20 12:13 - 2014-08-20 12:13 - 02101760 _____ (Farbar) C:\Users\***********\Desktop\FRST64.exe
2014-08-20 11:59 - 2014-08-20 11:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2014-08-19 10:58 - 2014-08-14 09:53 - 00843046 _____ () C:\Users\***********\Desktop\MyPhoneExplorer Client-com.fjsoft.myphoneexplorer.client-37-v1.0.34.apk
2014-08-19 10:54 - 2014-08-20 11:59 - 00002069 _____ () C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2014-08-19 10:53 - 2014-08-19 10:53 - 07326880 _____ () C:\Users\***********\Downloads\MyPhoneExplorer_Setup_1.8.6.exe
2014-08-19 10:39 - 2014-08-19 10:39 - 00000021 _____ () C:\Windows\S.dirmngr
2014-08-19 00:02 - 2014-08-19 00:02 - 02027770 _____ (FileZilla Project) C:\Users\***********\Downloads\FileZilla_Server-0_9_46.exe
2014-08-19 00:00 - 2014-08-19 00:00 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\REN8AEB.tmp
2014-08-19 00:00 - 2014-08-18 23:58 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\RENE4F7.tmp
2014-08-18 23:58 - 2014-08-19 00:00 - 00321448 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-18 23:58 - 2014-08-19 00:00 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-18 23:58 - 2014-08-19 00:00 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-18 23:58 - 2014-08-18 23:58 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\REN5DDA.tmp
2014-08-18 23:56 - 2014-08-18 23:59 - 162831776 _____ (Oracle Corporation) C:\Users\***********\Downloads\jdk-8u11-windows-x64.exe
2014-08-18 23:56 - 2014-08-18 23:57 - 31013800 _____ (Oracle Corporation) C:\Users\***********\Downloads\jre-7u67-windows-x64.exe
2014-08-17 15:28 - 2014-08-17 15:28 - 00017627 _____ () C:\Windows\DirectX.log
2014-08-17 14:14 - 2014-08-19 10:38 - 00001330 _____ () C:\Windows\PFRO.log
2014-08-17 12:08 - 2014-08-17 12:08 - 10373772 _____ () C:\Users\***********\Desktop\b.rar
2014-08-16 20:10 - 2014-08-16 20:10 - 15072932 _____ () C:\Users\***********\Desktop\Bir1.rar
2014-08-14 16:13 - 2014-08-14 16:13 - 00000000 ____D () C:\Users\***********\AppData\Local\Adobe
2014-08-14 14:06 - 2014-07-25 16:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-08-14 14:06 - 2014-07-25 15:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-14 14:06 - 2014-07-25 15:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-08-14 14:06 - 2014-07-25 14:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-08-14 14:06 - 2014-07-25 14:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-08-14 14:06 - 2014-07-25 14:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-08-14 14:06 - 2014-07-25 14:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-14 14:06 - 2014-07-25 14:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-08-14 14:06 - 2014-07-25 14:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-08-14 14:06 - 2014-07-25 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-14 14:06 - 2014-07-25 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-14 14:06 - 2014-07-25 13:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-14 14:06 - 2014-07-25 13:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-08-14 14:06 - 2014-07-25 13:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-08-14 14:06 - 2014-07-25 13:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-14 14:06 - 2014-07-25 13:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-14 14:06 - 2014-07-25 13:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-08-14 14:06 - 2014-07-25 13:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-14 14:06 - 2014-07-25 13:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-14 14:06 - 2014-07-25 13:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-14 14:06 - 2014-07-25 12:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-08-14 14:06 - 2014-07-25 12:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-08-14 14:06 - 2014-07-25 12:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-14 14:06 - 2014-07-25 12:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-14 14:05 - 2014-07-25 15:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-08-14 14:05 - 2014-07-25 15:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-08-14 14:05 - 2014-07-25 14:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-14 14:05 - 2014-07-25 14:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-14 14:05 - 2014-07-25 14:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-08-14 14:05 - 2014-07-25 13:43 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-08-14 14:05 - 2014-07-25 13:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-14 14:05 - 2014-07-25 13:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-08-14 14:05 - 2014-07-25 13:09 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-14 14:05 - 2014-07-25 12:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-08-14 14:05 - 2014-07-25 12:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-14 14:04 - 2014-06-20 03:48 - 01273184 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-08-14 14:04 - 2014-06-20 01:52 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-14 14:03 - 2014-06-13 03:15 - 00517528 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-08-14 14:03 - 2014-06-13 03:14 - 01557848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-08-14 14:03 - 2014-06-13 02:10 - 00406400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2014-08-14 14:03 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 14:03 - 2014-06-10 00:13 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-08-14 14:03 - 2014-06-06 13:34 - 02133504 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-08-14 14:02 - 2014-08-07 04:12 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-14 14:02 - 2014-08-07 00:39 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-14 14:02 - 2014-08-02 05:56 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-14 14:02 - 2014-08-02 05:11 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-08-14 14:02 - 2014-07-15 20:16 - 03048880 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe
2014-08-14 14:02 - 2014-07-15 10:29 - 03118080 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-08-14 14:02 - 2014-07-15 10:22 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebSync.dll
2014-08-14 14:02 - 2014-07-15 10:03 - 02344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll
2014-08-14 14:02 - 2014-07-12 06:17 - 00623616 _____ (Microsoft Corporation) C:\Windows\system32\MDMAgent.exe
2014-08-14 14:02 - 2014-06-05 16:13 - 00216368 _____ (Microsoft Corporation) C:\Windows\system32\rsaenh.dll
2014-08-14 14:02 - 2014-06-05 15:14 - 00189016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rsaenh.dll
2014-08-14 14:02 - 2014-06-04 11:27 - 00114520 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-08-14 14:02 - 2014-06-04 07:31 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-08-14 14:02 - 2014-06-04 07:22 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-08-14 14:02 - 2014-06-04 06:43 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-14 14:02 - 2014-06-04 06:38 - 03304448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-14 14:02 - 2014-06-04 04:15 - 02642944 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-08-14 14:02 - 2014-06-04 04:14 - 02318336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-14 14:02 - 2014-06-02 04:10 - 00423768 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-08-14 14:02 - 2014-05-31 12:07 - 00467800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2014-08-14 14:02 - 2014-05-31 12:07 - 00440664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-08-14 14:02 - 2014-05-31 12:07 - 00419672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-08-14 14:02 - 2014-05-31 12:07 - 00089944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-08-14 14:02 - 2014-05-31 12:07 - 00027480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-08-14 14:02 - 2014-05-31 08:30 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-08-14 14:02 - 2014-05-31 08:27 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-08-14 14:02 - 2014-05-31 08:26 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-08-14 14:02 - 2014-05-31 06:01 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-08-14 14:02 - 2014-05-31 06:01 - 00209408 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-08-14 14:02 - 2014-05-31 06:01 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-08-14 14:02 - 2014-05-29 08:21 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll
2014-08-14 14:02 - 2014-05-27 17:53 - 02518360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-08-14 14:02 - 2014-05-27 15:15 - 00705536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wnv.sys
2014-08-14 14:02 - 2014-05-27 15:15 - 00691200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmswitch.sys
2014-08-14 14:02 - 2014-05-27 12:23 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\vmsif.dll
2014-08-14 14:02 - 2014-05-27 11:56 - 00323584 _____ (Microsoft Corporation) C:\Windows\system32\DaOtpCredentialProvider.dll
2014-08-14 14:02 - 2014-05-27 11:53 - 00270848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DaOtpCredentialProvider.dll
2014-08-14 14:02 - 2014-05-17 06:59 - 16871936 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2014-08-14 14:02 - 2014-05-17 06:13 - 12711424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2014-08-14 14:02 - 2014-04-30 06:30 - 00668160 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2014-08-14 14:02 - 2014-04-30 05:52 - 00590336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
2014-08-11 13:08 - 2014-08-11 13:13 - 400353308 _____ () C:\Users\***********\Downloads\documents-export-2014-08-11.zip
2014-08-11 13:07 - 2014-08-11 13:07 - 08661142 _____ () C:\Users\***********\Downloads\gapps-jb-20130301-light.zip
2014-08-11 11:39 - 2014-08-19 10:58 - 00000795 _____ () C:\Windows\setupact.log
2014-08-11 11:39 - 2014-08-11 11:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-11 11:38 - 2014-08-11 11:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-10 23:03 - 2014-08-11 11:38 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-10 23:03 - 2014-08-10 23:03 - 00002782 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-10 23:02 - 2014-08-10 23:02 - 03738080 _____ (Piriform Ltd) C:\Users\***********\Downloads\ccsetup416_slim.exe
2014-08-05 19:59 - 2014-08-05 19:59 - 01806364 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-08-05 18:24 - 2014-08-05 18:28 - 00003392 _____ () C:\Windows\System32\Tasks\START SKYDRIVE
2014-08-04 21:34 - 2014-08-04 21:34 - 00000000 ____D () C:\Users\***********\AppData\Local\_3_
2014-08-04 21:32 - 2014-08-04 21:32 - 03670848 _____ (Passbild-Generator ) C:\Users\***********\Downloads\Setup4-Passbild-Generator.exe
2014-08-04 20:57 - 2014-08-04 20:57 - 00001476 _____ () C:\Users\***********\AppData\Local\recently-used.xbel
2014-08-03 19:17 - 2014-08-03 19:18 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2014-08-03 19:17 - 2014-08-03 19:18 - 00000000 ____D () C:\Program Files\Unlocker
2014-08-03 19:17 - 2014-08-03 19:17 - 01078591 _____ () C:\Users\***********\Downloads\Unlocker1.9.2.exe
2014-08-03 19:14 - 2014-08-18 23:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-08-03 19:11 - 2014-08-03 19:11 - 00895120 _____ (Google Inc.) C:\Users\***********\Downloads\googledrivesync(1).exe
2014-08-02 20:11 - 2014-08-02 20:20 - 00000000 ____D () C:\Users\***********\AppData\Local\Boxcryptor
2014-08-02 20:04 - 2014-08-02 20:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boxcryptor
2014-08-02 20:04 - 2014-08-02 20:04 - 00000000 ____D () C:\Program Files (x86)\Boxcryptor
2014-08-02 20:04 - 2013-11-15 14:45 - 00218408 _____ (EldoS Corporation) C:\Windows\SysWOW64\cbfsNetRdr4.dll
2014-08-02 20:04 - 2013-11-15 14:45 - 00120104 _____ (EldoS Corporation) C:\Windows\system32\cbfsNetRdr4.dll
2014-08-02 20:04 - 2013-11-15 14:45 - 00009000 _____ (EldoS Corporation) C:\Windows\system32\elevtmsg.dll
2014-08-02 20:04 - 2013-11-15 14:44 - 00183080 _____ (EldoS Corporation) C:\Windows\system32\cbfsMntNtf4.dll
2014-08-02 20:04 - 2013-11-15 14:43 - 00156456 _____ (EldoS Corporation) C:\Windows\SysWOW64\cbfsMntNtf4.dll
2014-08-02 20:04 - 2013-11-15 14:37 - 00387776 _____ (EldoS Corporation) C:\Windows\system32\Drivers\cbfs4.sys
2014-08-02 20:04 - 2013-11-15 14:37 - 00018624 _____ (EldoS Corporation) C:\Windows\system32\Drivers\vpnpbus.sys
2014-07-30 10:51 - 2014-07-30 10:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-29 14:49 - 2014-08-19 13:55 - 00005142 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for LAPTOP-*********** Laptop
2014-07-23 13:48 - 2014-07-10 06:16 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\SkyDriveTelemetry.dll
2014-07-23 13:48 - 2014-07-10 06:03 - 04756992 _____ (Microsoft Corporation) C:\Windows\system32\SyncEngine.dll
2014-07-23 13:48 - 2014-07-10 05:33 - 01120256 _____ (Microsoft Corporation) C:\Windows\system32\SkyDrive.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-20 12:18 - 2014-08-20 12:17 - 00034390 _____ () C:\Users\***********\Desktop\FRST.txt
2014-08-20 12:18 - 2014-08-20 12:17 - 00000000 ____D () C:\FRST
2014-08-20 12:17 - 2014-08-20 12:17 - 00028261 _____ () C:\Users\***********\Downloads\FRST.txt
2014-08-20 12:13 - 2014-08-20 12:13 - 02101760 _____ (Farbar) C:\Users\***********\Desktop\FRST64.exe
2014-08-20 12:09 - 2013-12-22 18:57 - 00000000 ____D () C:\Users\***********\.rainlendar2
2014-08-20 12:09 - 2013-12-22 18:40 - 00003942 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{1BB7D536-1F5B-413B-8245-25983FB0CF2D}
2014-08-20 12:07 - 2014-07-10 23:52 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-08-20 12:05 - 2013-12-22 18:40 - 00003594 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-22145797-4037712363-3399924978-1001
2014-08-20 12:02 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2014-08-20 11:59 - 2014-08-20 11:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyPhoneExplorer
2014-08-20 11:59 - 2014-08-19 10:54 - 00002069 _____ () C:\Users\Public\Desktop\MyPhoneExplorer.lnk
2014-08-20 11:59 - 2013-12-22 21:06 - 00000000 ____D () C:\Program Files (x86)\MyPhoneExplorer
2014-08-20 11:47 - 2014-08-20 11:47 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\***********\Downloads\mbam-setup-2.0.2.1012.exe
2014-08-20 11:35 - 2013-12-22 19:02 - 00001132 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-20 11:28 - 2013-12-22 18:30 - 01198428 _____ () C:\Windows\WindowsUpdate.log
2014-08-20 11:08 - 2013-12-22 18:32 - 01814802 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-08-20 11:08 - 2013-08-23 01:24 - 00784990 _____ () C:\Windows\system32\perfh007.dat
2014-08-20 11:08 - 2013-08-23 01:24 - 00165158 _____ () C:\Windows\system32\perfc007.dat
2014-08-20 11:07 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-08-19 23:34 - 2013-12-22 19:02 - 00001128 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-19 21:00 - 2014-08-17 15:40 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Tropico 4
2014-08-19 19:27 - 2014-01-26 19:33 - 00000000 ____D () C:\Program Files (x86)\Steam
2014-08-19 13:55 - 2014-07-29 14:49 - 00005142 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for LAPTOP-*********** Laptop
2014-08-19 11:51 - 2014-01-19 13:47 - 00531456 ___SH () C:\Users\***********\Desktop\Thumbs.db
2014-08-19 10:58 - 2014-08-11 11:39 - 00000795 _____ () C:\Windows\setupact.log
2014-08-19 10:58 - 2013-12-22 21:07 - 00000000 ____D () C:\Users\***********\AppData\Roaming\MyPhoneExplorer
2014-08-19 10:53 - 2014-08-19 10:53 - 07326880 _____ () C:\Users\***********\Downloads\MyPhoneExplorer_Setup_1.8.6.exe
2014-08-19 10:52 - 2013-12-22 18:37 - 00000000 ____D () C:\Users\***********\SkyDrive
2014-08-19 10:51 - 2013-12-22 19:04 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Dropbox
2014-08-19 10:50 - 2013-12-22 19:25 - 00000000 ____D () C:\Users\***********\AppData\Local\TSVNCache
2014-08-19 10:43 - 2014-02-09 13:39 - 27590656 _____ () C:\Windows\system32\vmguest.iso
2014-08-19 10:39 - 2014-08-19 10:39 - 00000021 _____ () C:\Windows\S.dirmngr
2014-08-19 10:39 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-19 10:38 - 2014-08-17 14:14 - 00001330 _____ () C:\Windows\PFRO.log
2014-08-19 00:05 - 2013-08-22 15:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-08-19 00:02 - 2014-08-19 00:02 - 02027770 _____ (FileZilla Project) C:\Users\***********\Downloads\FileZilla_Server-0_9_46.exe
2014-08-19 00:02 - 2014-05-18 12:07 - 00000000 ____D () C:\Program Files (x86)\FileZilla Server
2014-08-19 00:01 - 2013-12-22 20:00 - 00002868 _____ () C:\Windows\Sandboxie.ini
2014-08-19 00:00 - 2014-08-19 00:00 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\REN8AEB.tmp
2014-08-19 00:00 - 2014-08-18 23:58 - 00321448 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-08-19 00:00 - 2014-08-18 23:58 - 00191400 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-08-19 00:00 - 2014-08-18 23:58 - 00190888 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-08-19 00:00 - 2014-05-18 12:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-19 00:00 - 2014-05-18 12:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2014-08-19 00:00 - 2014-01-13 18:20 - 00000000 ____D () C:\Program Files\Java
2014-08-18 23:59 - 2014-08-18 23:56 - 162831776 _____ (Oracle Corporation) C:\Users\***********\Downloads\jdk-8u11-windows-x64.exe
2014-08-18 23:58 - 2014-08-19 00:00 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\RENE4F7.tmp
2014-08-18 23:58 - 2014-08-18 23:58 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\REN5DDA.tmp
2014-08-18 23:57 - 2014-08-18 23:56 - 31013800 _____ (Oracle Corporation) C:\Users\***********\Downloads\jre-7u67-windows-x64.exe
2014-08-18 23:35 - 2014-08-03 19:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2014-08-18 13:45 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\rescache
2014-08-18 13:38 - 2014-02-09 15:21 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-08-18 13:38 - 2014-01-26 21:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2014-08-17 15:28 - 2014-08-17 15:28 - 00017627 _____ () C:\Windows\DirectX.log
2014-08-17 14:40 - 2014-06-21 20:37 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2014-08-17 14:22 - 2013-12-22 19:08 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-08-17 14:15 - 2013-08-22 16:44 - 00723912 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-08-17 14:14 - 2013-12-22 18:58 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-08-17 14:12 - 2013-08-22 17:36 - 00000000 ___RD () C:\Windows\ToastData
2014-08-17 14:12 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-17 14:05 - 2014-01-16 16:06 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Spotify
2014-08-14 16:13 - 2014-08-14 16:13 - 00000000 ____D () C:\Users\***********\AppData\Local\Adobe
2014-08-14 16:04 - 2014-02-03 21:31 - 00000000 ____D () C:\Users\***********\AppData\Roaming\vlc
2014-08-14 14:19 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-08-14 14:18 - 2013-12-22 21:16 - 00000000 ____D () C:\Windows\system32\MRT
2014-08-14 14:14 - 2013-12-22 21:12 - 99218768 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-08-14 13:58 - 2014-06-12 00:19 - 00428888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-08-14 13:57 - 2014-06-28 22:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-08-14 13:57 - 2014-05-14 15:47 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-14 13:57 - 2014-05-14 15:07 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-08-14 13:57 - 2014-05-14 15:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-14 13:57 - 2014-05-14 14:58 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-14 13:57 - 2014-05-14 14:57 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-08-14 13:57 - 2014-05-14 14:57 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-14 13:57 - 2014-05-14 14:57 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-08-14 13:57 - 2014-05-14 14:57 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-08-14 13:57 - 2014-05-14 14:57 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-14 13:57 - 2014-05-14 14:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-08-14 13:57 - 2014-05-14 14:57 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-08-14 13:57 - 2014-05-14 14:57 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-14 13:57 - 2014-05-14 14:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-08-14 13:57 - 2014-04-10 10:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-14 13:57 - 2014-04-10 10:42 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-08-14 13:54 - 2014-07-10 23:52 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-08-14 09:53 - 2014-08-19 10:58 - 00843046 _____ () C:\Users\***********\Desktop\MyPhoneExplorer Client-com.fjsoft.myphoneexplorer.client-37-v1.0.34.apk
2014-08-11 23:33 - 2013-12-22 18:33 - 00000000 ____D () C:\Users\***********
2014-08-11 13:07 - 2014-08-11 13:07 - 08661142 _____ () C:\Users\***********\Downloads\gapps-jb-20130301-light.zip
2014-08-11 12:48 - 2013-12-22 21:10 - 00000000 ____D () C:\Users\***********\AppData\Local\Thunderbird
2014-08-11 12:41 - 2014-06-11 21:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-08-11 12:38 - 2014-05-30 22:27 - 00000000 ____D () C:\ProgramData\Origin
2014-08-11 11:39 - 2014-08-11 11:39 - 00000000 _____ () C:\Windows\setuperr.log
2014-08-11 11:38 - 2014-08-11 11:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-08-11 11:38 - 2014-08-10 23:03 - 00000000 ____D () C:\Program Files\CCleaner
2014-08-10 23:17 - 2014-05-30 22:27 - 00000000 ____D () C:\Program Files (x86)\Origin
2014-08-10 23:11 - 2014-07-20 19:19 - 00000000 ____D () C:\Users\***********\AppData\Roaming\TS3Client
2014-08-10 23:11 - 2013-12-27 13:30 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Notepad++
2014-08-10 23:11 - 2013-12-22 19:53 - 00000000 ____D () C:\Users\***********\AppData\Roaming\FileZilla
2014-08-10 23:03 - 2014-08-10 23:03 - 00002782 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2014-08-10 23:02 - 2014-08-10 23:02 - 03738080 _____ (Piriform Ltd) C:\Users\***********\Downloads\ccsetup416_slim.exe
2014-08-10 11:08 - 2014-01-16 16:07 - 00000000 ____D () C:\Users\***********\AppData\Local\Spotify
2014-08-10 00:34 - 2014-02-10 13:03 - 00000000 ____D () C:\Users\***********\Documents\OneNote-Notizbücher
2014-08-10 00:21 - 2013-12-23 01:09 - 00000000 ____D () C:\Users\***********\AppData\Roaming\gnupg
2014-08-08 19:49 - 2014-08-08 19:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2014-08-08 19:49 - 2014-08-08 18:40 - 00000000 ____D () C:\Users\***********\AppData\Local\EvernoteNW
2014-08-08 17:16 - 2014-01-26 21:23 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-08-08 14:47 - 2014-01-18 17:17 - 00001118 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 9.lnk
2014-08-08 14:34 - 2013-12-22 18:34 - 00000000 ____D () C:\Users\***********\AppData\Local\Packages
2014-08-07 04:12 - 2014-08-14 14:02 - 01336624 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-08-07 00:39 - 2014-08-14 14:02 - 04148224 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-08-05 20:45 - 2013-12-23 18:03 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-05 20:44 - 2014-04-26 18:41 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-05 20:44 - 2014-04-26 18:41 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-05 19:59 - 2014-08-05 19:59 - 01806364 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-08-05 19:56 - 2013-12-22 18:45 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-05 18:28 - 2014-08-05 18:24 - 00003392 _____ () C:\Windows\System32\Tasks\START SKYDRIVE
2014-08-04 21:34 - 2014-08-04 21:34 - 00000000 ____D () C:\Users\***********\AppData\Local\_3_
2014-08-04 21:34 - 2014-08-04 21:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Passbild-Generator
2014-08-04 21:34 - 2014-08-04 21:34 - 00000000 ____D () C:\Program Files (x86)\Passbild-Generator
2014-08-04 21:33 - 2014-08-04 21:33 - 03670848 _____ (Passbild-Generator ) C:\Users\***********\Downloads\Setup4-Passbild-Generator(1).exe
2014-08-04 21:32 - 2014-08-04 21:32 - 03670848 _____ (Passbild-Generator ) C:\Users\***********\Downloads\Setup4-Passbild-Generator.exe
2014-08-04 20:57 - 2014-08-04 20:57 - 00001476 _____ () C:\Users\***********\AppData\Local\recently-used.xbel
2014-08-04 20:57 - 2014-02-11 20:08 - 00000000 ____D () C:\Users\***********\.gimp-2.8
2014-08-04 16:36 - 2014-01-13 18:17 - 00000000 ____D () C:\Program Files\eclipse
2014-08-04 01:15 - 2014-01-23 12:39 - 00000000 ____D () C:\Users\***********\AppData\Local\TGitCache
2014-08-04 01:15 - 2014-01-23 12:36 - 00000000 ____D () C:\Program Files\TortoiseGit
2014-08-04 01:15 - 2014-01-23 12:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TortoiseGit
2014-08-03 19:18 - 2014-08-03 19:17 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
2014-08-03 19:18 - 2014-08-03 19:17 - 00000000 ____D () C:\Program Files\Unlocker
2014-08-03 19:17 - 2014-08-03 19:17 - 01078591 _____ () C:\Users\***********\Downloads\Unlocker1.9.2.exe
2014-08-03 19:14 - 2013-12-22 19:02 - 00000000 ____D () C:\Program Files (x86)\Google
2014-08-03 19:11 - 2014-08-03 19:11 - 00895120 _____ (Google Inc.) C:\Users\***********\Downloads\googledrivesync(1).exe
2014-08-02 20:20 - 2014-08-02 20:11 - 00000000 ____D () C:\Users\***********\AppData\Local\Boxcryptor
2014-08-02 20:06 - 2013-12-23 18:09 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-08-02 20:06 - 2013-12-23 18:09 - 00000000 ____D () C:\Program Files (x86)\Microsoft Silverlight
2014-08-02 20:04 - 2014-08-02 20:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boxcryptor
2014-08-02 20:04 - 2014-08-02 20:04 - 00000000 ____D () C:\Program Files (x86)\Boxcryptor
2014-08-02 20:03 - 2014-03-01 12:52 - 00000000 ____D () C:\Users\***********\AppData\Roaming\Skype
2014-08-02 05:56 - 2014-08-14 14:02 - 01064448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-02 05:11 - 2014-08-14 14:02 - 00918528 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2014-08-02 02:17 - 2014-05-17 23:12 - 00704480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-08-02 02:17 - 2014-05-17 23:12 - 00105440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-30 11:08 - 2014-06-11 13:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak
2014-07-30 10:51 - 2014-07-30 10:51 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-07-25 16:52 - 2014-08-14 14:06 - 23645696 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-07-25 15:51 - 2014-08-14 14:06 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-25 15:28 - 2014-08-14 14:05 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-07-25 15:25 - 2014-08-14 14:06 - 02774528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-07-25 15:25 - 2014-08-14 14:05 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-07-25 14:59 - 2014-08-14 14:06 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-07-25 14:40 - 2014-08-14 14:06 - 00452096 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-07-25 14:34 - 2014-08-14 14:05 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-25 14:30 - 2014-08-14 14:05 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-25 14:28 - 2014-08-14 14:06 - 05824512 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-07-25 14:28 - 2014-08-14 14:05 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-07-25 14:21 - 2014-08-14 14:06 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-25 14:17 - 2014-08-14 14:06 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-07-25 14:10 - 2014-08-14 14:06 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-07-25 14:08 - 2014-08-14 14:06 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-25 14:06 - 2014-08-14 14:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-25 13:52 - 2014-08-14 14:06 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-25 13:47 - 2014-08-14 14:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-07-25 13:43 - 2014-08-14 14:05 - 00333312 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-07-25 13:43 - 2014-08-14 14:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-25 13:42 - 2014-08-14 14:05 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-07-25 13:39 - 2014-08-14 14:06 - 02087936 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-07-25 13:34 - 2014-08-14 14:06 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-25 13:29 - 2014-08-14 14:06 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-25 13:23 - 2014-08-14 14:06 - 13547008 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-07-25 13:13 - 2014-08-14 14:06 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-25 13:09 - 2014-08-14 14:05 - 00291840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-25 13:07 - 2014-08-14 14:06 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-25 13:03 - 2014-08-14 14:06 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-25 12:52 - 2014-08-14 14:05 - 02266624 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-07-25 12:26 - 2014-08-14 14:06 - 01431040 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-07-25 12:17 - 2014-08-14 14:06 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-07-25 12:09 - 2014-08-14 14:06 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-25 12:05 - 2014-08-14 14:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-25 12:00 - 2014-08-14 14:06 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-24 15:38 - 2013-12-23 18:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-07-24 14:30 - 2014-04-27 11:06 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
Some content of TEMP:
====================
C:\Users\***********\AppData\Local\Temp\avgnt.exe
C:\Users\***********\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpdn8h00.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-08-10 17:21
==================== End Of Log ============================ --- --- ---
--- --- --- |