Hallo,
so, folgendes kam dabei raus:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 13.09.2014 09:22:24, SYSTEM, SARA, Protection, Malware Protection, Starting,
Protection, 13.09.2014 09:22:24, SYSTEM, SARA, Protection, Malware Protection, Started,
Protection, 13.09.2014 09:22:24, SYSTEM, SARA, Protection, Malicious Website Protection, Starting,
Protection, 13.09.2014 09:22:25, SYSTEM, SARA, Protection, Malicious Website Protection, Started,
Update, 13.09.2014 09:22:30, SYSTEM, SARA, Manual, Rootkit Database, 2014.2.20.1, 2014.9.12.1,
Update, 13.09.2014 09:22:42, SYSTEM, SARA, Manual, Malware Database, 2014.3.4.9, 2014.9.13.1,
Protection, 13.09.2014 09:22:43, SYSTEM, SARA, Protection, Refresh, Starting,
Protection, 13.09.2014 09:22:43, SYSTEM, SARA, Protection, Malicious Website Protection, Stopping,
Protection, 13.09.2014 09:22:43, SYSTEM, SARA, Protection, Malicious Website Protection, Stopped,
Protection, 13.09.2014 09:22:47, SYSTEM, SARA, Protection, Refresh, Success,
Protection, 13.09.2014 09:22:47, SYSTEM, SARA, Protection, Malicious Website Protection, Starting,
Protection, 13.09.2014 09:22:47, SYSTEM, SARA, Protection, Malicious Website Protection, Started,
Protection, 13.09.2014 09:46:41, SYSTEM, SARA, Protection, Malware Protection, Starting,
Protection, 13.09.2014 09:46:42, SYSTEM, SARA, Protection, Malware Protection, Started,
Protection, 13.09.2014 09:46:42, SYSTEM, SARA, Protection, Malicious Website Protection, Starting,
Protection, 13.09.2014 09:47:46, SYSTEM, SARA, Protection, Malicious Website Protection, Started,
(end)
AdwCleaner Logfile:
Code:
# AdwCleaner v3.310 - Bericht erstellt am 13/09/2014 um 10:03:24
# Aktualisiert 12/09/2014 von Xplode
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Sara L - SARA
# Gestartet von : C:\Users\Sara L\Downloads\AdwCleaner_3.310.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\WPM
Ordner Gelöscht : C:\Program Files (x86)\Browser App
Ordner Gelöscht : C:\Program Files (x86)\globalUpdate
Ordner Gelöscht : C:\Program Files (x86)\predm
Ordner Gelöscht : C:\Program Files (x86)\RegClean Pro
Ordner Gelöscht : C:\Users\Sara L\AppData\Local\globalUpdate
Ordner Gelöscht : C:\Users\Sara L\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\Sara L\AppData\Roaming\UpdaterEX
Datei Gelöscht : C:\END
Datei Gelöscht : C:\WINDOWS\System32\roboot64.exe
Datei Gelöscht : C:\Users\Sara L\AppData\Roaming\aps.uninstall.scan.results
Datei Gelöscht : C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage
Datei Gelöscht : C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxp_www.azlyrics.com_0.localstorage-journal
***** [ Tasks ] *****
Task Gelöscht : APSnotifierPP1
Task Gelöscht : APSnotifierPP2
Task Gelöscht : APSnotifierPP3
Task Gelöscht : Optimizer Pro Schedule
Task Gelöscht : UpdaterEX
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [AnyProtect Scanner]
Schlüssel Gelöscht : HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\Application\IePluginServices
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKCU\Software\AnyProtect
Schlüssel Gelöscht : HKCU\Software\Conduit
Schlüssel Gelöscht : HKCU\Software\genesis
Schlüssel Gelöscht : HKCU\Software\GlobalUpdate
Schlüssel Gelöscht : HKCU\Software\IM
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\Softonic
Schlüssel Gelöscht : HKCU\Software\systweak
Schlüssel Gelöscht : HKCU\Software\Tuto4PC
Schlüssel Gelöscht : HKCU\Software\UpdaterEX
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{5F189DF5-2D05-472B-9091-84D9848AE48B}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
Schlüssel Gelöscht : HKLM\SOFTWARE\GlobalUpdate
Schlüssel Gelöscht : HKLM\SOFTWARE\SoftwareUpdater
Schlüssel Gelöscht : HKLM\SOFTWARE\systweak
Schlüssel Gelöscht : HKLM\SOFTWARE\Tutorials
Schlüssel Gelöscht : HKLM\SOFTWARE\Vittalia
Daten Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows [AppInit_DLLs] - C:\PROGRA~2\SupTab\SEARCH~2.DLL
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17278
-\\ Mozilla Firefox v
-\\ Google Chrome v36.0.1985.125
[ Datei : C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\preferences ]
Gelöscht [Startup_urls] : hxxp://www.trovi.com/?gd=&ctid=CT3318399&octid=EB_ORIGINAL_CTID&ISID=M2CD19A53-D634-41F5-A7CB-568D5A6F034E&SearchSource=55&CUI=&UM=6&UP=SPA4968DF3-422B-4312-B6B9-B7A5E5DBBCD9&SSPV=
Gelöscht [Homepage] : hxxp://www.trovi.com/?gd=&ctid=CT3318399&octid=EB_ORIGINAL_CTID&ISID=M2CD19A53-D634-41F5-A7CB-568D5A6F034E&SearchSource=55&CUI=&UM=6&UP=SPA4968DF3-422B-4312-B6B9-B7A5E5DBBCD9&SSPV=
Gelöscht [Extension] : booedmolknjekdopkepjjeckmjkdpfgl
Gelöscht [Extension] : flpcjncodpafbgdpnkljologafpionhb
*************************
AdwCleaner[R0].txt - [5614 octets] - [13/09/2014 09:56:41]
AdwCleaner[S0].txt - [4920 octets] - [13/09/2014 10:03:24]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4980 octets] ##########
--- --- ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Sara L on 13.09.2014 at 10:19:42,90
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 13.09.2014 at 10:25:11,07
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014
Ran by Sara L (administrator) on SARA on 13-09-2014 10:27:21
Running from C:\Users\Sara L\Downloads
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(ABBYY) C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\agent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-08-30] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [AnyProtect Tray] => "C:\Program Files (x86)\AnyProtectEx\AnyProtectTrayIcon.exe"
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2014-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [751184 2014-07-23] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-25] (Oracle Corporation)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46952 2011-08-02] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [30568 2011-08-02] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139264 2013-04-05] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4522496 2012-12-27] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [2009088 2013-01-18] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [164656 2014-08-27] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-1802224982-3330714616-2264724891-1001\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATIHJE.EXE [283232 2014-05-21] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1802224982-3330714616-2264724891-1001\...\Run: [BrowserChoice] => C:\Windows\BrowserChoice\browserchoice.exe [86816 2013-08-22] (Microsoft Corporation)
HKU\S-1-5-21-1802224982-3330714616-2264724891-1001\...\Run: [ABBYY Screenshot Reader Bonus] => C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint\Bonus.ScreenshotReader.exe [939272 2009-11-25] (ABBYY)
HKU\S-1-5-21-1802224982-3330714616-2264724891-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {BFB8B63F-E9DF-4442-B0ED-64064FD4C196} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS
SearchScopes: HKLM-x32 - {BFB8B63F-E9DF-4442-B0ED-64064FD4C196} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MASBJS
BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll (Zeon Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Sara L\AppData\Roaming\Mozilla\Firefox\Profiles\fCD0z5i0.default
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Avira Browser Safety - C:\Users\Sara L\AppData\Roaming\Mozilla\Firefox\Profiles\fCD0z5i0.default\Extensions\abs@avira.com [2014-08-18]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR DefaultSuggestURL: Default -> hxxp://suggest.seccint.com/CSuggestJson.ashx?prefix={searchTerms}
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.4.600\_platform_specific\win_x86\widevinecdmadapter.dll No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\36.0.1985.125\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Profile: C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (ProxFlow) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2014-05-21]
CHR Extension: (Google Drive) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-16]
CHR Extension: (YouTube) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-16]
CHR Extension: (Google-Suche) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-16]
CHR Extension: (Avira Browser Safety) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2014-08-18]
CHR Extension: (AdBlock) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-05-17]
CHR Extension: (Google Wallet) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-16]
CHR Extension: (Google Mail) - C:\Users\Sara L\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-16]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [430160 2014-07-23] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [430160 2014-07-23] (Avira Operations GmbH & Co. KG)
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [160048 2014-08-27] (Avira Operations GmbH & Co. KG)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2012-10-26] (Brother Industries, Ltd.) [File not signed]
R3 KeyIso; C:\Windows\SysWOW64\keyiso.dll [44032 2013-08-22] (Microsoft Corporation)
S3 lfsvc; C:\Windows\SysWOW64\GeofenceMonitorService.dll [357376 2014-05-23] (Microsoft Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
S3 Netlogon; C:\Windows\SysWOW64\netlogon.dll [688640 2014-05-23] (Microsoft Corporation)
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [145256 2011-08-02] (Nuance Communications, Inc.)
S3 smphost; C:\Windows\SysWOW64\smphost.dll [11776 2013-08-22] (Microsoft Corporation)
S3 StorSvc; C:\Windows\SysWOW64\storsvc.dll [18944 2013-08-22] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-05-23] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-05-23] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [36096 2013-05-21] (Advanced Micro Devices, Inc.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-07-23] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [130584 2014-07-23] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2014-07-23] (Avira Operations GmbH & Co. KG)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-13] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-05-23] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-13 10:27 - 2014-09-13 10:27 - 02105856 _____ (Farbar) C:\Users\Sara L\Downloads\FRST64.exe
2014-09-13 10:25 - 2014-09-13 10:25 - 00000615 _____ () C:\Users\Sara L\Desktop\JRT.txt
2014-09-13 10:19 - 2014-09-13 10:19 - 01016261 _____ (Thisisu) C:\Users\Sara L\Downloads\JRT.exe
2014-09-13 10:19 - 2014-09-13 10:19 - 01016261 _____ (Thisisu) C:\Users\Sara L\Downloads\JRT (1).exe
2014-09-13 10:19 - 2014-09-13 10:19 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-09-13 10:09 - 2014-09-13 10:09 - 00005076 _____ () C:\Users\Sara L\Desktop\AdwCleaner[S0].txt
2014-09-13 09:57 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-09-13 09:56 - 2014-09-13 10:03 - 00000000 ____D () C:\AdwCleaner
2014-09-13 09:54 - 2014-09-13 09:54 - 01373475 _____ () C:\Users\Sara L\Downloads\AdwCleaner_3.310.exe
2014-09-13 09:53 - 2014-09-13 09:53 - 00001578 _____ () C:\Users\Sara L\Desktop\mbam.txt
2014-09-13 09:22 - 2014-09-13 10:07 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-13 09:21 - 2014-09-13 09:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-13 09:21 - 2014-09-13 09:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 09:21 - 2014-09-13 09:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-13 09:21 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-09-13 09:21 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-09-13 09:21 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-09-13 09:20 - 2014-09-13 09:20 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sara L\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-12 20:03 - 2014-09-12 20:03 - 00067904 _____ () C:\Users\Sara L\Downloads\HA. 11.09.odt
2014-09-12 11:32 - 2014-09-12 11:32 - 00031733 _____ () C:\Users\Sara L\Downloads\Addition.txt
2014-09-12 11:30 - 2014-09-13 10:27 - 00015032 _____ () C:\Users\Sara L\Downloads\FRST.txt
2014-09-12 11:30 - 2014-09-13 10:27 - 00000000 ____D () C:\FRST
2014-09-12 10:13 - 2014-09-13 10:05 - 00006058 _____ () C:\WINDOWS\PFRO.log
2014-09-11 23:03 - 2014-09-11 23:03 - 00001160 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-11 20:46 - 2014-08-16 04:40 - 23591424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-09-11 20:46 - 2014-08-16 04:00 - 02793984 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-09-11 20:46 - 2014-08-16 03:56 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-09-11 20:46 - 2014-08-16 03:54 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-09-11 20:46 - 2014-08-16 03:43 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-09-11 20:46 - 2014-08-16 03:32 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-09-11 20:46 - 2014-08-16 03:25 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-09-11 20:46 - 2014-08-16 03:22 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-09-11 20:46 - 2014-08-16 03:20 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-09-11 20:46 - 2014-08-16 03:19 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-09-11 20:46 - 2014-08-16 03:18 - 02185728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-09-11 20:46 - 2014-08-16 03:18 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-09-11 20:46 - 2014-08-16 03:11 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-09-11 20:46 - 2014-08-16 03:06 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-09-11 20:46 - 2014-08-16 03:05 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-09-11 20:46 - 2014-08-16 03:05 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-09-11 20:46 - 2014-08-16 03:03 - 02104832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-09-11 20:46 - 2014-08-16 03:03 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-09-11 20:46 - 2014-08-16 02:58 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-09-11 20:46 - 2014-08-16 02:56 - 02310656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-09-11 20:46 - 2014-08-16 02:53 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-09-11 20:46 - 2014-08-16 02:53 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-09-11 20:46 - 2014-08-16 02:45 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-09-11 20:46 - 2014-08-16 02:44 - 02014208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-09-11 20:46 - 2014-08-16 02:44 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-09-11 20:46 - 2014-08-16 02:34 - 01447424 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-09-11 20:46 - 2014-08-16 02:20 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-09-11 20:46 - 2014-08-16 02:18 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-09-11 20:46 - 2014-08-16 02:14 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-09-11 20:46 - 2014-08-16 02:12 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-09-11 20:45 - 2014-08-16 04:04 - 17455104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-09-11 20:45 - 2014-08-16 04:00 - 05833728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-09-11 20:45 - 2014-08-16 03:45 - 04232704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-09-11 20:45 - 2014-08-16 02:53 - 13588480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-09-11 20:45 - 2014-08-16 02:51 - 11769856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-09-11 10:43 - 2014-09-11 10:43 - 00540962 _____ () C:\Users\Sara L\Downloads\anaphase.flv
2014-09-10 23:41 - 2014-09-10 23:41 - 00000000 ___RD () C:\Users\Sara L\AppData\Roaming\Brother
2014-09-10 22:41 - 2014-08-02 02:18 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2014-09-10 22:41 - 2014-07-24 05:20 - 00875688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2014-09-10 22:41 - 2014-07-24 05:20 - 00869544 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2014-09-05 10:55 - 2014-09-05 10:55 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\FLEXnet
2014-09-05 10:55 - 2014-09-05 10:55 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\ControlCenter4
2014-09-04 22:01 - 2014-09-11 21:48 - 00000000 ____D () C:\Users\Sara L\Documents\Schule
2014-09-04 22:01 - 2014-09-04 22:01 - 00010240 ___SH () C:\Users\Sara L\Documents\Thumbs.db
2014-09-04 21:31 - 2014-09-04 21:31 - 00002167 _____ () C:\Users\Public\Desktop\Brother Creative Center.lnk
2014-09-04 21:31 - 2014-09-04 21:31 - 00002082 _____ () C:\Users\Public\Desktop\Brother Utilities.lnk
2014-09-04 21:31 - 2014-09-04 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
2014-09-04 21:30 - 2014-09-04 21:30 - 00000092 _____ () C:\WINDOWS\brpcfx.ini
2014-09-04 21:30 - 2014-09-04 21:30 - 00000024 _____ () C:\WINDOWS\Brpfx04a.ini
2014-09-04 21:30 - 2014-09-04 21:30 - 00000000 ____D () C:\Users\Public\Documents\BrFaxRx
2014-09-04 21:30 - 2014-09-04 21:30 - 00000000 ____D () C:\Brother
2014-09-04 21:29 - 2014-09-04 21:30 - 00000066 _____ () C:\WINDOWS\Brfaxrx.ini
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\ProgramData\PCFaxTx
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\ProgramData\ControlCenter4
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\Program Files (x86)\ControlCenter4
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\Program Files (x86)\Browny02
2014-09-04 21:29 - 2013-03-04 06:49 - 00180224 _____ (Brother Industries, Ltd.) C:\WINDOWS\SysWOW64\BROSNMP.DLL
2014-09-04 21:29 - 2013-03-03 18:01 - 00227328 _____ (Brother Industries, Ltd.) C:\WINDOWS\system32\BRCOI13A.DLL
2014-09-04 21:29 - 2012-12-12 11:37 - 00318464 ____N (Brother Industries, Ltd.) C:\WINDOWS\system32\BrFaxTxAppRun64.dll
2014-09-04 21:29 - 2012-11-09 13:13 - 00324096 ____R (brother) C:\WINDOWS\system32\NSSRH64.dll
2014-09-04 21:29 - 2012-10-29 05:50 - 00065024 ____R (Brother Industries,Ltd) C:\WINDOWS\system32\Brnsplg.dll
2014-09-04 21:29 - 2012-10-19 14:06 - 00059392 ____R (Brother Industries,Ltd.) C:\WINDOWS\system32\BrWiaNCp.dll
2014-09-04 21:29 - 2012-10-19 14:02 - 00087040 ____R (Brother Industries, Ltd.) C:\WINDOWS\system32\BrNetSti.dll
2014-09-04 21:29 - 2005-04-22 06:36 - 00143360 ____R () C:\WINDOWS\system32\BrSNMP64.dll
2014-09-04 21:28 - 2014-09-04 21:30 - 00000000 ____D () C:\Program Files (x86)\Brother
2014-09-04 21:28 - 2013-01-10 13:56 - 00253952 ____N (brother) C:\WINDOWS\SysWOW64\NSSearch.dll
2014-09-04 21:28 - 2012-10-22 14:41 - 00002560 ____N (Brother Industries Ltd.) C:\WINDOWS\SysWOW64\BrDctF2S.dll
2014-09-04 21:28 - 2010-03-15 19:45 - 00073728 ____N (Brother Industries Ltd.) C:\WINDOWS\SysWOW64\BrDctF2.dll
2014-09-04 21:28 - 2007-12-13 22:16 - 00005632 ____N (Brother Industries Ltd.) C:\WINDOWS\SysWOW64\BrDctF2L.dll
2014-09-04 21:23 - 2014-09-12 16:57 - 00015605 _____ () C:\WINDOWS\BRRBCOM.INI
2014-09-04 21:23 - 2014-09-04 21:23 - 00007819 _____ () C:\WINDOWS\BROMJ470DW.INI
2014-09-04 21:09 - 2014-09-04 21:09 - 00000000 ____D () C:\ProgramData\zeon
2014-09-04 21:09 - 2014-09-04 21:09 - 00000000 ____D () C:\Program Files\Nuance
2014-09-04 21:08 - 2014-09-05 11:39 - 00000000 ____D () C:\ProgramData\Nuance
2014-09-04 21:08 - 2014-09-04 21:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance PaperPort 12
2014-09-04 21:08 - 2014-09-04 21:09 - 00000000 ____D () C:\Program Files (x86)\Nuance
2014-09-04 21:08 - 2014-09-04 21:08 - 00001893 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Software Updates.lnk
2014-09-04 21:08 - 2014-09-04 21:08 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\Nuance
2014-09-04 21:08 - 2014-09-04 21:08 - 00000000 ____D () C:\ProgramData\ScanSoft
2014-09-04 21:08 - 2014-09-04 21:08 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-09-04 21:06 - 2014-09-04 21:23 - 00000000 ____D () C:\ProgramData\Brother
2014-09-04 21:06 - 2014-09-04 21:06 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-08-29 10:32 - 2014-08-29 10:33 - 00000000 ____D () C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2014-08-29 10:32 - 2014-08-29 10:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 9.0 Sprint
2014-08-28 22:50 - 2014-08-28 22:50 - 00000000 ____D () C:\ProgramData\Sun
2014-08-28 22:50 - 2014-08-28 22:50 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-28 22:50 - 2014-08-28 22:49 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-08-28 22:49 - 2014-08-28 22:50 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-28 22:49 - 2014-08-28 22:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-08-28 22:49 - 2014-08-28 22:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-08-28 22:49 - 2014-08-28 22:49 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-08-28 22:49 - 2014-08-28 22:49 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-28 22:46 - 2014-08-28 22:46 - 00918440 _____ (Oracle Corporation) C:\Users\Sara L\Downloads\chromeinstall-7u67.exe
2014-08-28 19:45 - 2014-08-23 02:42 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-28 19:45 - 2014-08-07 04:12 - 01336624 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2014-08-28 19:45 - 2014-08-02 05:56 - 01064448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2014-08-27 00:52 - 2014-08-27 00:52 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\OpenOffice
2014-08-26 23:07 - 2014-08-26 23:07 - 00001132 _____ () C:\Users\Sara L\Desktop\OpenOffice 4.1.1.lnk
2014-08-26 23:07 - 2014-08-26 23:07 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-08-26 23:06 - 2014-08-26 23:06 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-08-26 22:57 - 2014-08-26 23:02 - 164858324 _____ () C:\Users\Sara L\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe
2014-08-18 11:02 - 2014-08-18 11:02 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\Avira
2014-08-18 10:58 - 2014-08-18 10:57 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2014-08-18 10:56 - 2014-07-23 13:29 - 00130584 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2014-08-18 10:56 - 2014-07-23 13:29 - 00117712 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2014-08-18 10:56 - 2014-07-23 13:29 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2014-08-18 10:54 - 2014-08-18 10:54 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\Mozilla
2014-08-18 10:53 - 2014-09-11 23:03 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-18 10:53 - 2014-09-11 23:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-08-18 10:53 - 2014-09-11 23:03 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-18 10:53 - 2014-08-18 10:56 - 00000000 ____D () C:\ProgramData\Avira
2014-08-18 10:53 - 2014-08-18 10:53 - 04574968 _____ (Avira Operations GmbH & Co. KG) C:\Users\Sara L\Downloads\avira_de_av___ws.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-09-13 10:27 - 2014-09-13 10:27 - 02105856 _____ (Farbar) C:\Users\Sara L\Downloads\FRST64.exe
2014-09-13 10:27 - 2014-09-12 11:30 - 00015032 _____ () C:\Users\Sara L\Downloads\FRST.txt
2014-09-13 10:27 - 2014-09-12 11:30 - 00000000 ____D () C:\FRST
2014-09-13 10:26 - 2014-05-15 21:48 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1802224982-3330714616-2264724891-1001
2014-09-13 10:25 - 2014-09-13 10:25 - 00000615 _____ () C:\Users\Sara L\Desktop\JRT.txt
2014-09-13 10:19 - 2014-09-13 10:19 - 01016261 _____ (Thisisu) C:\Users\Sara L\Downloads\JRT.exe
2014-09-13 10:19 - 2014-09-13 10:19 - 01016261 _____ (Thisisu) C:\Users\Sara L\Downloads\JRT (1).exe
2014-09-13 10:19 - 2014-09-13 10:19 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-09-13 10:12 - 2014-05-16 10:56 - 00001120 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-09-13 10:09 - 2014-09-13 10:09 - 00005076 _____ () C:\Users\Sara L\Desktop\AdwCleaner[S0].txt
2014-09-13 10:07 - 2014-09-13 09:22 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-09-13 10:07 - 2014-08-01 22:06 - 00000000 __RDO () C:\Users\Sara L\OneDrive
2014-09-13 10:07 - 2014-05-16 10:57 - 00002202 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-09-13 10:06 - 2014-05-16 10:56 - 00001116 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-09-13 10:06 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-09-13 10:05 - 2014-09-12 10:13 - 00006058 _____ () C:\WINDOWS\PFRO.log
2014-09-13 10:05 - 2013-08-22 15:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-09-13 10:04 - 2014-08-12 08:47 - 01258721 _____ () C:\WINDOWS\WindowsUpdate.log
2014-09-13 10:03 - 2014-09-13 09:56 - 00000000 ____D () C:\AdwCleaner
2014-09-13 10:00 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-09-13 09:54 - 2014-09-13 09:54 - 01373475 _____ () C:\Users\Sara L\Downloads\AdwCleaner_3.310.exe
2014-09-13 09:53 - 2014-09-13 09:53 - 00001578 _____ () C:\Users\Sara L\Desktop\mbam.txt
2014-09-13 09:44 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Web
2014-09-13 09:22 - 2014-09-13 09:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-09-13 09:21 - 2014-09-13 09:21 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-09-13 09:21 - 2014-09-13 09:21 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-09-13 09:20 - 2014-09-13 09:20 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Sara L\Downloads\mbam-setup-2.0.2.1012.exe
2014-09-13 09:05 - 2014-07-01 10:48 - 00003918 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{7C81715A-EDC7-4793-9095-60F5800BD9F4}
2014-09-13 09:04 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-09-12 23:37 - 2014-05-19 22:36 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\Skype
2014-09-12 20:03 - 2014-09-12 20:03 - 00067904 _____ () C:\Users\Sara L\Downloads\HA. 11.09.odt
2014-09-12 16:57 - 2014-09-04 21:23 - 00015605 _____ () C:\WINDOWS\BRRBCOM.INI
2014-09-12 11:32 - 2014-09-12 11:32 - 00031733 _____ () C:\Users\Sara L\Downloads\Addition.txt
2014-09-12 10:55 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-09-12 10:40 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-09-12 10:14 - 2013-08-22 16:44 - 00362792 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-09-12 00:30 - 2014-05-16 23:57 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-09-12 00:27 - 2014-05-16 23:57 - 101694776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-09-11 23:03 - 2014-09-11 23:03 - 00001160 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-09-11 23:03 - 2014-08-18 10:53 - 00000000 ____D () C:\ProgramData\Package Cache
2014-09-11 23:03 - 2014-08-18 10:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2014-09-11 23:03 - 2014-08-18 10:53 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-09-11 21:48 - 2014-09-04 22:01 - 00000000 ____D () C:\Users\Sara L\Documents\Schule
2014-09-11 20:46 - 2014-06-11 16:03 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msrating.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrating.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00139264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieUnatt.exe
2014-09-11 20:46 - 2014-06-11 16:03 - 00112128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieUnatt.exe
2014-09-11 20:46 - 2014-06-11 16:03 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2014-09-11 20:46 - 2014-06-11 16:03 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iesetup.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieetwproxystub.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwproxystub.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iernonce.dll
2014-09-11 20:46 - 2014-06-11 16:03 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollectorres.dll
2014-09-11 20:46 - 2014-05-23 12:20 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2014-09-11 20:46 - 2014-05-23 12:20 - 02724864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2014-09-11 10:43 - 2014-09-11 10:43 - 00540962 _____ () C:\Users\Sara L\Downloads\anaphase.flv
2014-09-11 00:20 - 2014-07-09 18:19 - 00040960 ___SH () C:\Users\Sara L\Downloads\Thumbs.db
2014-09-10 23:42 - 2014-05-16 00:55 - 00000000 ____D () C:\Users\Sara L\AppData\Local\CrashDumps
2014-09-10 23:41 - 2014-09-10 23:41 - 00000000 ___RD () C:\Users\Sara L\AppData\Roaming\Brother
2014-09-08 11:55 - 2014-06-20 15:24 - 00000000 ____D () C:\Users\Sara L\Documents\Unterlagen
2014-09-05 11:39 - 2014-09-04 21:08 - 00000000 ____D () C:\ProgramData\Nuance
2014-09-05 10:55 - 2014-09-05 10:55 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\FLEXnet
2014-09-05 10:55 - 2014-09-05 10:55 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\ControlCenter4
2014-09-04 22:01 - 2014-09-04 22:01 - 00010240 ___SH () C:\Users\Sara L\Documents\Thumbs.db
2014-09-04 21:31 - 2014-09-04 21:31 - 00002167 _____ () C:\Users\Public\Desktop\Brother Creative Center.lnk
2014-09-04 21:31 - 2014-09-04 21:31 - 00002082 _____ () C:\Users\Public\Desktop\Brother Utilities.lnk
2014-09-04 21:31 - 2014-09-04 21:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
2014-09-04 21:30 - 2014-09-04 21:30 - 00000092 _____ () C:\WINDOWS\brpcfx.ini
2014-09-04 21:30 - 2014-09-04 21:30 - 00000024 _____ () C:\WINDOWS\Brpfx04a.ini
2014-09-04 21:30 - 2014-09-04 21:30 - 00000000 ____D () C:\Users\Public\Documents\BrFaxRx
2014-09-04 21:30 - 2014-09-04 21:30 - 00000000 ____D () C:\Brother
2014-09-04 21:30 - 2014-09-04 21:29 - 00000066 _____ () C:\WINDOWS\Brfaxrx.ini
2014-09-04 21:30 - 2014-09-04 21:28 - 00000000 ____D () C:\Program Files (x86)\Brother
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\ProgramData\PCFaxTx
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\ProgramData\ControlCenter4
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\Program Files (x86)\ControlCenter4
2014-09-04 21:29 - 2014-09-04 21:29 - 00000000 ____D () C:\Program Files (x86)\Browny02
2014-09-04 21:28 - 2014-05-21 13:50 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-09-04 21:23 - 2014-09-04 21:23 - 00007819 _____ () C:\WINDOWS\BROMJ470DW.INI
2014-09-04 21:23 - 2014-09-04 21:06 - 00000000 ____D () C:\ProgramData\Brother
2014-09-04 21:09 - 2014-09-04 21:09 - 00000000 ____D () C:\ProgramData\zeon
2014-09-04 21:09 - 2014-09-04 21:09 - 00000000 ____D () C:\Program Files\Nuance
2014-09-04 21:09 - 2014-09-04 21:08 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance PaperPort 12
2014-09-04 21:09 - 2014-09-04 21:08 - 00000000 ____D () C:\Program Files (x86)\Nuance
2014-09-04 21:08 - 2014-09-04 21:08 - 00001893 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Software Updates.lnk
2014-09-04 21:08 - 2014-09-04 21:08 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\Nuance
2014-09-04 21:08 - 2014-09-04 21:08 - 00000000 ____D () C:\ProgramData\ScanSoft
2014-09-04 21:08 - 2014-09-04 21:08 - 00000000 ____D () C:\ProgramData\FLEXnet
2014-09-04 21:06 - 2014-09-04 21:06 - 00000000 ____D () C:\Program Files (x86)\MSXML 4.0
2014-09-02 22:06 - 2013-08-22 17:38 - 00706016 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2014-09-02 22:06 - 2013-08-22 17:38 - 00105440 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2014-08-31 19:05 - 2014-05-19 22:36 - 00000000 ____D () C:\ProgramData\Skype
2014-08-29 10:33 - 2014-08-29 10:32 - 00000000 ____D () C:\Program Files (x86)\ABBYY FineReader 9.0 Sprint
2014-08-29 10:32 - 2014-08-29 10:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 9.0 Sprint
2014-08-29 10:17 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp
2014-08-28 22:50 - 2014-08-28 22:50 - 00000000 ____D () C:\ProgramData\Sun
2014-08-28 22:50 - 2014-08-28 22:50 - 00000000 ____D () C:\ProgramData\Oracle
2014-08-28 22:50 - 2014-08-28 22:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-08-28 22:49 - 2014-08-28 22:50 - 00272808 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaws.exe
2014-08-28 22:49 - 2014-08-28 22:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\javaw.exe
2014-08-28 22:49 - 2014-08-28 22:49 - 00175528 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\java.exe
2014-08-28 22:49 - 2014-08-28 22:49 - 00098216 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2014-08-28 22:49 - 2014-08-28 22:49 - 00000000 ____D () C:\Program Files (x86)\Java
2014-08-28 22:46 - 2014-08-28 22:46 - 00918440 _____ (Oracle Corporation) C:\Users\Sara L\Downloads\chromeinstall-7u67.exe
2014-08-27 00:52 - 2014-08-27 00:52 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\OpenOffice
2014-08-26 23:07 - 2014-08-26 23:07 - 00001132 _____ () C:\Users\Sara L\Desktop\OpenOffice 4.1.1.lnk
2014-08-26 23:07 - 2014-08-26 23:07 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-08-26 23:06 - 2014-08-26 23:06 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-08-26 23:04 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-08-26 23:02 - 2014-08-26 22:57 - 164858324 _____ () C:\Users\Sara L\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe
2014-08-26 22:57 - 2014-05-15 16:33 - 00000000 ____D () C:\Users\Sara L\AppData\Local\Packages
2014-08-23 18:45 - 2014-03-18 12:03 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-08-23 18:45 - 2014-03-18 11:25 - 00764340 _____ () C:\WINDOWS\system32\perfh007.dat
2014-08-23 18:45 - 2014-03-18 11:25 - 00159160 _____ () C:\WINDOWS\system32\perfc007.dat
2014-08-23 02:42 - 2014-08-28 19:45 - 04148224 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-08-19 22:26 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\PolicyDefinitions
2014-08-19 08:43 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-08-19 08:43 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\MediaViewer
2014-08-19 08:43 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\FileManager
2014-08-19 08:43 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\Camera
2014-08-18 11:56 - 2014-07-24 08:33 - 00000000 ____D () C:\ProgramData\dealsTer
2014-08-18 11:02 - 2014-08-18 11:02 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\Avira
2014-08-18 10:57 - 2014-08-18 10:58 - 00042040 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2014-08-18 10:56 - 2014-08-18 10:53 - 00000000 ____D () C:\ProgramData\Avira
2014-08-18 10:54 - 2014-08-18 10:54 - 00000000 ____D () C:\Users\Sara L\AppData\Roaming\Mozilla
2014-08-18 10:53 - 2014-08-18 10:53 - 04574968 _____ (Avira Operations GmbH & Co. KG) C:\Users\Sara L\Downloads\avira_de_av___ws.exe
2014-08-16 04:40 - 2014-09-11 20:46 - 23591424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-08-16 04:04 - 2014-09-11 20:45 - 17455104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-08-16 04:00 - 2014-09-11 20:46 - 02793984 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-08-16 04:00 - 2014-09-11 20:45 - 05833728 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-08-16 03:56 - 2014-09-11 20:46 - 00547328 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2014-08-16 03:54 - 2014-09-11 20:46 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2014-08-16 03:45 - 2014-09-11 20:45 - 04232704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-08-16 03:43 - 2014-09-11 20:46 - 00758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2014-08-16 03:32 - 2014-09-11 20:46 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-08-16 03:25 - 2014-09-11 20:46 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\JavaScriptCollectionAgent.dll
2014-08-16 03:22 - 2014-09-11 20:46 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2014-08-16 03:20 - 2014-09-11 20:46 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2014-08-16 03:19 - 2014-09-11 20:46 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-08-16 03:18 - 2014-09-11 20:46 - 02185728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-08-16 03:18 - 2014-09-11 20:46 - 00289280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-08-16 03:11 - 2014-09-11 20:46 - 00597504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2014-08-16 03:06 - 2014-09-11 20:46 - 00359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-08-16 03:05 - 2014-09-11 20:46 - 00727040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-08-16 03:05 - 2014-09-11 20:46 - 00707072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-08-16 03:03 - 2014-09-11 20:46 - 02104832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-08-16 03:03 - 2014-09-11 20:46 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-08-16 02:58 - 2014-09-11 20:46 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-16 02:56 - 2014-09-11 20:46 - 02310656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-08-16 02:53 - 2014-09-11 20:46 - 00243200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-08-16 02:53 - 2014-09-11 20:46 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-08-16 02:53 - 2014-09-11 20:45 - 13588480 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-08-16 02:51 - 2014-09-11 20:45 - 11769856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-08-16 02:45 - 2014-09-11 20:46 - 00603136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-08-16 02:44 - 2014-09-11 20:46 - 02014208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-08-16 02:44 - 2014-09-11 20:46 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-08-16 02:34 - 2014-09-11 20:46 - 01447424 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-08-16 02:20 - 2014-09-11 20:46 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-08-16 02:18 - 2014-09-11 20:46 - 00775168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-08-16 02:14 - 2014-09-11 20:46 - 01190400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-08-16 02:12 - 2014-09-11 20:46 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
Some content of TEMP:
====================
C:\Users\Sara L\AppData\Local\Temp\avgnt.exe
C:\Users\Sara L\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-09-05 10:37
==================== End Of Log ============================
--- --- ---
Besten Dank!
Viele Grüße