robertine | 23.11.2014 17:44 | Hallo Schrauber,
erst einmal Danke für Deine schnelle Antwort und die Anweisungen.
Arbeite sie Schritt für Schritt ab, stehe jetzt aber vor einem Problem.
Bei Malwarebytes/ Code:
Anwendungsprotokolle - Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
- Wähle das neueste Suchlauf-Protokoll aus und klicke auf Ansicht.
beim Suchlauf-Protokoll kann ich Ansicht nicht anklicken, es steht nur "Alle llöschen" zur Verfügung.
Habe alles vom Bildschirm abfotografiert, damit ich meine Handlungen nachvollziehen kann, konnte da aber keinen Fehler feststellen.
Lasse den Computer jetzt mal so stehen - schreiben tue ich wieder vom XP, damit ich immer nachschauen kann.
Vielen Dank für Deine Geduld mit mir, bin immer sehr unsicher.
Lieben Gruß
robertine
es hat nun doch geklappt und arbeite jetzt die anderen Punkte ab
hoffe, dass ich nicht noch mehr Fehler produziere
lieben Gruß robertine
Hallo Schrauber,
hatte gerade schon gseschrieben und plötzlich hat sich die Seite verabschiedet
deshalb die Dateien getrennt - erst einmal die mbam.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 23.11.2014
Suchlauf-Zeit: 15:12:57
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.3.1025
Malware Datenbank: v2014.11.23.05
Rootkit Datenbank: v2014.11.22.01
Lizenz: Testversion
Malware Schutz: Aktiviert
Bösartiger Webseiten Schutz: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: karin
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 322518
Verstrichene Zeit: 7 Min, 31 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 4
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\updateEnterDigital.exe, 22544, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab]
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\EnterDigital.BrowserAdapter.exe, 7232, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab]
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\EnterDigital.BrowserAdapter64.exe, 6748, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab]
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\utilEnterDigital.exe, 3788, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab]
Module: 1
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{bf07813e-aac8-4cea-bf69-7178c16076ac}.dll, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
Registrierungsschlüssel: 23
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{5513f398-67f7-4a89-b91e-d74c4cd0fb67}, In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{5513F398-67F7-4A89-B91E-D74C4CD0FB67}, In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\., In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\..9, In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\., In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\WOW6432NODE\CLASSES\..9, In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{5513F398-67F7-4A89-B91E-D74C4CD0FB67}, In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.MultiPlug, HKLM\SOFTWARE\CLASSES\CLSID\{5513F398-67F7-4A89-B91E-D74C4CD0FB67}\INPROCSERVER32, In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [032e76c984f838fed7936f889d6557a9],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [032e76c984f838fed7936f889d6557a9],
PUP.Optional.EnterDigital.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update EnterDigital, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util EnterDigital, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.Sanbreel.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{16fd1cfd-5f7d-4fb7-ac6e-55eec1f56bf3}Gw64, In Quarantäne, [54ddd966502c67cfdebe0649da2945bb],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2436487137-2019308104-1651275924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [0829f54a1d5f261044c9f1885ba8df21],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2436487137-2019308104-1651275924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [87aadd620874bd79d1716b2428dca15f],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-2436487137-2019308104-1651275924-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 1Y1L1M1G1I1Q, In Quarantäne, [87aadd620874bd79d1716b2428dca15f]
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 7
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\TEMP, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
Rogue.Multiple, C:\ProgramData\374311380, In Quarantäne, [fa37d46b92ea91a573f7eb102dd55aa6],
PUP.Optional.Vosteran.A, C:\Users\karin\AppData\Roaming\WSE_Vosteran, In Quarantäne, [c869e35ccbb170c6e3fe86b347bcfb05],
PUP.Optional.Vosteran.A, C:\Users\karin\AppData\Roaming\WSE_Vosteran\icons_3.6.2.0, In Quarantäne, [c869e35ccbb170c6e3fe86b347bcfb05],
Dateien: 51
PUP.Optional.MultiPlug, C:\ProgramData\deal2dealit\n6ecqSumkqfICD.x64.dll, In Quarantäne, [85ac6ad559236accfd58f4cc29d86997],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\EnterDigitalbho.dll, In Quarantäne, [50e1da65fb8162d47797a33ad72ad030],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\EnterDigital.ico, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\0, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\7za.exe, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\ghpmlbobkefgcgihkmhnbkepebhfbamm.crx, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\updateEnterDigital.exe, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\updateEnterDigital.InstallState, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\bau, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\16fd1cfd5f7d4fb7ac6e.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\16fd1cfd5f7d4fb7ac6e64.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\7za.exe, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\8ca7f15054544b4c9537.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\8ca7f15054544b4c953764.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\b28b16f8524c4f96b046.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\b28b16f8524c4f96b04664.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\bf07813eaac84ceabf69.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\bf07813eaac84ceabf6964.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\BrowserAdapter.7z, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\EnterDigital.BrowserAdapter.exe, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\EnterDigital.BrowserAdapter64.exe, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\EnterDigital.iz, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\EnterDigital.PurBrowseG.zip, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\sqlite3.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\tmp5D32.tmp, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\tmp600E.tmp, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\tmp87A6.tmp, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\utilEnterDigital.exe, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\utilEnterDigital.InstallState, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{16fd1cfd-5f7d-4fb7-ac6e-55eec1f56bf3}.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{16fd1cfd-5f7d-4fb7-ac6e-55eec1f56bf3}64.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{8ca7f150-5454-4b4c-9537-1b831c71d329}.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{8ca7f150-5454-4b4c-9537-1b831c71d329}64.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{b28b16f8-524c-4f96-b046-1c8f12a5fe03}.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{b28b16f8-524c-4f96-b046-1c8f12a5fe03}64.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{bf07813e-aac8-4cea-bf69-7178c16076ac}.dll, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\{bf07813e-aac8-4cea-bf69-7178c16076ac}64.dll, Löschen bei Neustart, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.BOAS.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.Bromon.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.BroStats.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.BrowserAdapter.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.BRT.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.CompatibilityChecker.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.FFUpdate.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.GCUpdate.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.IEUpdate.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.Msvcmon.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.EnterDigital.A, C:\Program Files (x86)\EnterDigital\bin\plugins\EnterDigital.PurBrowseG.dll, In Quarantäne, [9998d06ff08c69cd1dd1b18d6c9755ab],
PUP.Optional.Sanbreel.A, C:\Windows\System32\drivers\{16fd1cfd-5f7d-4fb7-ac6e-55eec1f56bf3}Gw64.sys, In Quarantäne, [54ddd966502c67cfdebe0649da2945bb],
Malware.Trace, C:\Windows\regedit.log, In Quarantäne, [131e85ba7efe71c5f9d698863aca9070],
Rogue.Multiple, C:\ProgramData\374311380\BITCDF6.tmp, In Quarantäne, [fa37d46b92ea91a573f7eb102dd55aa6],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) die nächste kommt gleich...
Hallo Schrauber,
er hatte sich schon wieder verabschiedet..
aber hier kommt die AdwCleaner Code:
# AdwCleaner v4.101 - Bericht erstellt am 23/11/2014 um 16:21:11
# Aktualisiert 09/11/2014 von Xplode
# Database : 2014-11-23.4 [Live]
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : karin - KARINKOEPPEL
# Gestartet von : C:\Users\karin\Desktop\AdwCleaner_4.101.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\deal2dealit
Ordner Gelöscht : C:\ProgramData\GoldenCoupon
Ordner Gelöscht : C:\ProgramData\e8e8a6a6cf9f411e
Ordner Gelöscht : C:\Users\karin\AppData\Local\Pokki
Ordner Gelöscht : C:\Users\karin\AppData\Local\Temp\EnterDigital
Ordner Gelöscht : C:\Users\karin\Documents\Optimizer Pro
Ordner Gelöscht : C:\Users\Public\Pokki
Datei Gelöscht : C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage
Datei Gelöscht : C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_www.superfish.com_0.localstorage-journal
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
Schlüssel Gelöscht : HKCU\Software\Classes\AllFileSystemObjects\shell\pokki
Schlüssel Gelöscht : HKCU\Software\Classes\Directory\shell\pokki
Schlüssel Gelöscht : HKCU\Software\Classes\Drive\shell\pokki
Schlüssel Gelöscht : HKCU\Software\Classes\lnkfile\shell\pokki
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[#] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{56FDF344-FD6D-11D0-958A-006097C9A090}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AA9A4890-4262-4441-8977-E2FFCBFB706C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{772A39EF-A0CB-496E-9FD0-9C0494318335}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{772A39EF-A0CB-496E-9FD0-9C0494318335}
Schlüssel Gelöscht : HKCU\Software\OCS
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\Pokki
Schlüssel Gelöscht : HKCU\Software\EnterDigital
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\EnterDigital
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\vosteran.com
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17037
-\\ Mozilla Firefox v33.1 (x86 de)
[9z8u49j2.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.hmpgUrl", "hxxp://Vosteran.com/?f=1&a=vst_ggbc_14_46_ff&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyE0CtBtDyCtDzytBtA0FyDtN0D0Tzu0StCtDyEzytN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDyD1[...]
[9z8u49j2.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.newTabUrl", "hxxp://Vosteran.com/?f=2&a=vst_ggbc_14_46_ff&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyE0CtBtDyCtDzytBtA0FyDtN0D0Tzu0StCtDyEzytN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzytDy[...]
[9z8u49j2.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.prtnrId", "WSE_Vosteran");
[9z8u49j2.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.srchPrvdr", "Vosteran");
[9z8u49j2.default\prefs.js] - Zeile gelöscht : user_pref("extensions.srchvstrn.tlbrSrchUrl", "hxxp://Vosteran.com/?f=3&a=vst_ggbc_14_46_ff&cd=2XzuyEtN2Y1L1Qzu0CyEyDyEyEyE0CtBtDyCtDzytBtA0FyDtN0D0Tzu0StCtDyEzytN1L2XzutAtFyCtFtBtFtDtN1L1CzutCyEtBzyt[...]
-\\ Google Chrome v35.0.1916.114
[C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\preferences] - Gelöscht [Extension] : eofcbnmajmjmplflapaojjnihcjkigck
-\\ Opera v26.0.1656.24
*************************
AdwCleaner[R0].txt - [5309 octets] - [23/11/2014 16:18:17]
AdwCleaner[S0].txt - [4841 octets] - [23/11/2014 16:21:11]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4901 octets] ########## jetzt muss ich nur noch die Junkware bearbeiten und hoffe, es geht etwas schneller
Lieben Gruß robertine
so, hier kommt die JRT - melde mich dann gleich wieder.... Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.9 (11.15.2014:2)
OS: Windows 8.1 x64
Ran by karin on 23.11.2014 at 17:22:05,91
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23.11.2014 at 17:27:50,17
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Hallo Schrauber,
hier kommt nun der Rest und ich hoffe, dass alles OK ist.
Werde nun meine Schutzsoftware wieder anstellen. Soll ich da gleich einen Durchlauf machen?
Erst einmal herzlichen Dank für Deine Unterstützung
mit lieben Gruß robertine
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2014
Ran by karin (administrator) on KARINKOEPPEL on 23-11-2014 17:34:08
Running from C:\Users\karin\Desktop
Loaded Profile: karin (Available profiles: karin)
Platform: Windows 8.1 (Update 1) (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Spotify Ltd) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QuickAccess.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(TODO: <Company name>) C:\Program Files\Acer\User Experience Improvement Program\Plugin\AppMonitor\AppMonitorPlugIn.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2199840 2014-03-26] (NVIDIA Corporation)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [217088 2014-06-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [62208 2014-11-17] (Acer Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-21] (AVAST Software)
HKLM-x32\...\Run: [abDocsDllLoader] => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [90368 2014-11-20] ()
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\...\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-08-14] (Spotify Ltd)
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\...\Run: [HP Officejet 4620 series (NET)] => C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
Startup: C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series.lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [ACloudSyncedRF] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncedSF] -> {5D5F18B7-D59B-4B18-A3E9-0A4BDCCCB699} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM -> DefaultScope {772A39EF-A0CB-496E-9FD0-9C0494318335} URL =
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {772A39EF-A0CB-496E-9FD0-9C0494318335} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2436487137-2019308104-1651275924-1001 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-2436487137-2019308104-1651275924-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-2436487137-2019308104-1651275924-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\karin\AppData\Roaming\Mozilla\Firefox\Profiles\9z8u49j2.default
FF DefaultSearchUrl: hxxp://www.bing.com/search
FF SearchEngineOrder.1: Microsoft (Bing)
FF Homepage: hxxp://www.msn.com/?pc=AV01
FF Keyword.URL: hxxp://www.bing.com/search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\karin\AppData\Roaming\Mozilla\Firefox\Profiles\9z8u49j2.default\searchplugins\bing-avast.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-14]
FF Extension: No Name - wrc@avast.com [Not Found]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-14]
CHR Extension: (Google Drive) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-14]
CHR Extension: (YouTube) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-14]
CHR Extension: (Google Search) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-14]
CHR Extension: (EnterDigital) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghpmlbobkefgcgihkmhnbkepebhfbamm [2014-11-18]
CHR Extension: (Avast Online Security) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-14]
CHR Extension: (Google Wallet) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-14]
CHR Extension: (Gmail) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-14]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx []
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-21]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-21] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-21] (Avast Software)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [94208 2014-05-06] () [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2709760 2014-11-17] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573544 2014-03-21] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-07] (WildTangent)
R2 HPSLPSVC; C:\Users\karin\AppData\Local\Temp\7zS1C45\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [459496 2014-03-17] (Acer Incorporate)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1616160 2014-03-26] (NVIDIA Corporation)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457960 2014-03-21] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-03-21] (Acer Incorporate)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-24] (acer)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [111208 2014-11-14] (RaMMicHaeL)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-08-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-08-14] (Microsoft Corporation)
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\siteadvisor\mcsacore.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-21] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-21] ()
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
U5 GeneStor; C:\Windows\System32\Drivers\GeneStor.sys [111336 2014-04-28] (GenesysLogic)
R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [24568 2013-10-03] (Intel Corporation)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [99320 2013-10-03] (Intel Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-23] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-10-01] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [573144 2014-04-18] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3468504 2014-05-22] (Realtek Semiconductor Corporation )
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-20] (Synaptics Incorporated)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-21] (Avast Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-08-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-23 17:33 - 2014-11-23 17:33 - 00000000 ____D () C:\Users\karin\Desktop\FRST-OlderVersion
2014-11-23 17:27 - 2014-11-23 17:27 - 00000748 _____ () C:\Users\karin\Desktop\JRT.txt
2014-11-23 17:22 - 2014-11-23 17:22 - 00000000 ____D () C:\Windows\ERUNT
2014-11-23 17:12 - 2014-11-23 17:12 - 01707532 _____ (Thisisu) C:\Users\karin\Desktop\JRT.exe
2014-11-23 16:32 - 2014-11-23 16:32 - 00000197 _____ () C:\Windows\system32\2014-11-23-15-32-30.081-AvastVBoxSVC.exe-2964.log
2014-11-23 16:21 - 2014-11-23 16:21 - 00004997 _____ () C:\Users\karin\Desktop\AdwCleaner[S0].txt
2014-11-23 16:17 - 2014-11-23 16:43 - 00000000 ____D () C:\AdwCleaner
2014-11-23 16:11 - 2014-11-23 16:11 - 02140160 _____ () C:\Users\karin\Desktop\AdwCleaner_4.101.exe
2014-11-23 15:52 - 2014-11-23 15:52 - 00013992 _____ () C:\Users\karin\Desktop\mbam.txt
2014-11-23 15:27 - 2014-11-23 15:27 - 00000197 _____ () C:\Windows\system32\2014-11-23-14-27-47.012-AvastVBoxSVC.exe-2788.log
2014-11-23 15:11 - 2014-11-23 17:19 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-23 15:10 - 2014-11-23 15:10 - 00001122 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-23 15:10 - 2014-11-23 15:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-23 15:10 - 2014-11-23 15:10 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-23 15:10 - 2014-11-23 15:10 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-23 15:10 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-23 15:10 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-23 15:10 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-23 15:02 - 2014-11-23 15:02 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\karin\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-23 14:44 - 2014-11-23 14:50 - 00001288 _____ () C:\Users\karin\Desktop\Revo Uninstaller.lnk
2014-11-23 14:44 - 2014-11-23 14:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-11-23 14:40 - 2014-11-23 14:40 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\karin\Downloads\revosetup95.exe
2014-11-21 20:44 - 2014-11-21 20:45 - 00000000 ____D () C:\Users\karin\Internet- Foren
2014-11-21 20:33 - 2014-11-23 17:34 - 00020513 _____ () C:\Users\karin\Desktop\FRST.txt
2014-11-21 20:33 - 2014-11-21 20:35 - 00035268 _____ () C:\Users\karin\Desktop\Addition.txt
2014-11-21 20:32 - 2014-11-23 17:34 - 00000000 ____D () C:\FRST
2014-11-21 20:27 - 2014-11-21 20:28 - 02117632 _____ (Farbar) C:\Users\karin\Downloads\FRST64(1).exe
2014-11-21 20:24 - 2014-11-23 17:33 - 02118144 _____ (Farbar) C:\Users\karin\Desktop\FRST64.exe
2014-11-21 19:56 - 2014-11-21 19:56 - 00000247 _____ () C:\Windows\system32\2014-11-21-18-56-22.023-aswFe.exe-11548.log
2014-11-21 19:46 - 2014-11-21 19:56 - 00000247 _____ () C:\Windows\system32\2014-11-21-18-46-39.093-aswFe.exe-3564.log
2014-11-21 19:46 - 2014-11-21 19:46 - 00000197 _____ () C:\Windows\system32\2014-11-21-18-46-30.070-AvastVBoxSVC.exe-3384.log
2014-11-21 19:21 - 2014-11-21 19:21 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-11-21 19:21 - 2014-11-21 19:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-11-20 17:33 - 2014-11-20 17:33 - 00000197 _____ () C:\Windows\system32\2014-11-20-16-33-32.051-AvastVBoxSVC.exe-2884.log
2014-11-20 17:31 - 2014-11-20 17:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-11-20 12:27 - 2014-11-20 12:27 - 00000000 ____D () C:\Users\karin\Documents\My Bluetooth
2014-11-17 08:26 - 2014-11-21 00:00 - 00000000 ____D () C:\Users\karin\Documents\eigene Dokumente
2014-11-17 08:06 - 2014-11-17 08:08 - 00005632 ___SH () C:\Users\karin\Documents\Thumbs.db
2014-11-17 08:06 - 2014-11-17 08:06 - 00007334 _____ () C:\Users\karin\Documents\OpenDocument Text (neu).odt
2014-11-16 07:48 - 2014-11-16 07:48 - 00001141 _____ () C:\Users\karin\Desktop\Bilder - Verknüpfung.lnk
2014-11-16 06:41 - 2014-11-16 06:41 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-11-16 01:00 - 2014-11-16 01:00 - 00167997 _____ () C:\Users\karin\Documents\2014_09_lebens kosten-geändert_1.ods
2014-11-15 00:10 - 2014-11-18 16:06 - 00000000 ____D () C:\Users\karin\Documents\Finanzen
2014-11-15 00:04 - 2014-11-15 00:04 - 00001872 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! antivirus.lnk
2014-11-14 23:13 - 2014-11-14 23:15 - 00000000 ____D () C:\Users\karin\Programme
2014-11-14 22:01 - 2014-11-14 22:01 - 00000247 _____ () C:\Windows\system32\2014-11-14-21-01-17.044-aswFe.exe-7492.log
2014-11-14 21:58 - 2014-11-14 22:01 - 00000247 _____ () C:\Windows\system32\2014-11-14-20-58-36.060-aswFe.exe-6532.log
2014-11-14 21:58 - 2014-11-14 21:58 - 00000197 _____ () C:\Windows\system32\2014-11-14-20-58-34.023-AvastVBoxSVC.exe-5192.log
2014-11-14 21:54 - 2014-11-14 21:54 - 00000000 ____D () C:\Windows\SysWOW64\vbox
2014-11-14 21:54 - 2014-11-14 21:54 - 00000000 ____D () C:\Windows\system32\vbox
2014-11-14 21:23 - 2014-11-14 21:23 - 00000000 ____D () C:\ProgramData\7bb6df21-8ca8-4eec-965d-8cd2261544c7
2014-11-14 21:13 - 2014-11-14 21:13 - 00000000 ____D () C:\Users\karin\AppData\Roaming\AVAST Software
2014-11-14 21:13 - 2014-11-14 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-11-14 21:13 - 2014-11-14 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2014-11-14 21:12 - 2014-11-23 17:17 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-14 21:12 - 2014-11-23 16:31 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-14 21:12 - 2014-11-23 15:28 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-11-14 21:12 - 2014-11-21 19:22 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-11-14 21:12 - 2014-11-21 19:21 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-11-14 21:12 - 2014-11-14 21:13 - 00000000 ____D () C:\Users\karin\AppData\Local\Google
2014-11-14 21:12 - 2014-11-14 21:13 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-14 21:12 - 2014-11-14 21:12 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-14 21:12 - 2014-11-14 21:12 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-14 21:11 - 2014-11-14 21:11 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-11-14 21:11 - 2014-11-14 21:11 - 00000000 ____D () C:\Program Files\AVAST Software
2014-11-14 21:09 - 2014-11-14 21:10 - 131078000 _____ (AVAST Software) C:\Users\karin\Downloads\avast_free_antivirus_setup.exe
2014-11-14 21:08 - 2014-11-14 21:08 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Opera Software
2014-11-14 21:08 - 2014-11-14 21:08 - 00000000 ____D () C:\Users\karin\AppData\Local\Opera Software
2014-11-14 21:07 - 2014-11-21 19:15 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-11-14 21:07 - 2014-11-20 17:37 - 00003860 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1415995658
2014-11-14 21:07 - 2014-11-20 17:37 - 00001061 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-11-14 21:06 - 2014-11-14 21:06 - 00870264 _____ (Opera Software) C:\Users\karin\Downloads\Opera_NI_stable.exe
2014-11-14 20:26 - 2014-11-14 20:26 - 00000000 ____D () C:\Users\karin\AppData\Local\Macromedia
2014-11-14 20:24 - 2014-11-23 16:58 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-14 20:24 - 2014-11-20 12:58 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-14 20:24 - 2014-11-14 21:13 - 00000000 ____D () C:\Users\karin\AppData\Local\Adobe
2014-11-14 20:07 - 2014-11-14 20:07 - 00000000 ____D () C:\Users\karin\AppData\Roaming\OpenOffice
2014-11-14 20:05 - 2014-11-14 20:05 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-11-14 20:04 - 2014-11-14 23:35 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-11-14 19:56 - 2014-11-21 20:53 - 00000000 ____D () C:\Users\karin\AppData\Roaming\HpUpdate
2014-11-14 19:55 - 2014-11-14 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-11-14 19:55 - 2014-11-14 19:56 - 00000000 ____D () C:\Program Files (x86)\HP
2014-11-14 19:55 - 2014-11-14 19:55 - 00000057 _____ () C:\ProgramData\Ament.ini
2014-11-14 19:55 - 2014-11-14 19:55 - 00000000 ____D () C:\Program Files\HP
2014-11-14 19:55 - 2012-10-17 04:31 - 00741480 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPM6412.dll
2014-11-14 19:53 - 2014-11-14 19:56 - 00000000 ____D () C:\Users\karin\AppData\Local\HP
2014-11-14 19:49 - 2014-11-14 19:55 - 00000000 ____D () C:\ProgramData\HP
2014-11-14 19:49 - 2014-11-14 19:52 - 164858324 _____ () C:\Users\karin\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe
2014-11-14 19:46 - 2014-11-14 19:47 - 19904818 _____ () C:\Users\karin\Downloads\Apache_OpenOffice_4.1.1_Win_x86_langpack_de.exe
2014-11-14 19:39 - 2014-11-14 21:13 - 00000000 ____D () C:\ProgramData\Unchecky
2014-11-14 19:39 - 2014-11-14 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky
2014-11-14 19:39 - 2014-11-14 19:39 - 00000000 ____D () C:\Program Files (x86)\Unchecky
2014-11-14 19:34 - 2014-11-14 19:34 - 02338824 _____ () C:\Users\karin\Downloads\hppiw.exe
2014-11-14 15:38 - 2014-11-14 15:38 - 00285810 ____T () C:\Users\karin\Documents\2014-11-14_Fritz-sichern-2.oxps
2014-11-14 15:34 - 2014-11-14 15:34 - 00284722 ____T () C:\Users\karin\Documents\2014-11-14_Fritz-sichern.oxps
2014-11-12 00:57 - 2014-11-12 00:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-11-11 14:32 - 2014-11-11 14:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-10 00:31 - 2014-11-10 00:31 - 00000000 ____D () C:\Users\karin\AppData\Roaming\WildTangent
2014-11-10 00:31 - 2014-11-10 00:31 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-11-09 20:42 - 2014-11-09 20:42 - 00002118 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-11-09 20:42 - 2014-11-09 20:42 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Thunderbird
2014-11-09 20:42 - 2014-11-09 20:42 - 00000000 ____D () C:\Users\karin\AppData\Local\Thunderbird
2014-11-09 20:42 - 2014-11-09 20:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-11-09 20:23 - 2014-11-09 20:25 - 26315072 _____ (Mozilla) C:\Users\karin\Downloads\Thunderbird Setup 31.2.0.exe
2014-11-09 20:03 - 2014-11-14 21:14 - 00001155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-09 20:03 - 2014-11-12 07:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-09 20:03 - 2014-11-09 20:13 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Mozilla
2014-11-09 20:03 - 2014-11-09 20:13 - 00000000 ____D () C:\Users\karin\AppData\Local\Mozilla
2014-11-09 20:03 - 2014-11-09 20:03 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-09 18:22 - 2014-11-11 14:12 - 00000000 ____D () C:\Users\karin\AppData\Local\Acer
2014-11-09 05:54 - 2014-11-23 17:31 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0F5C2207-F544-488A-BB6D-D07B19818EA9}
2014-11-09 05:54 - 2014-11-09 05:54 - 00000000 __SHD () C:\Users\karin\AppData\Local\EmieUserList
2014-11-09 05:54 - 2014-11-09 05:54 - 00000000 __SHD () C:\Users\karin\AppData\Local\EmieSiteList
2014-11-09 05:54 - 2014-11-09 05:54 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Macromedia
2014-11-09 05:36 - 2014-11-20 20:52 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Spotify
2014-11-09 05:36 - 2014-11-09 05:36 - 00000000 ____D () C:\Users\karin\AppData\Local\Spotify
2014-11-09 05:35 - 2014-11-09 05:35 - 00000000 ____D () C:\Users\karin\AppData\Local\Acer Aspire R7 Tutorial
2014-11-09 05:25 - 2014-11-09 05:25 - 00000000 ____D () C:\Users\karin\AppData\Local\iGware
2014-11-08 05:21 - 2014-11-23 14:22 - 00000000 ____D () C:\Users\karin\AppData\Local\CrashDumps
2014-11-08 05:01 - 2014-11-08 05:01 - 00003334 _____ () C:\Windows\System32\Tasks\AcerCloud
2014-11-08 04:53 - 2014-11-23 16:36 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2436487137-2019308104-1651275924-1001
2014-11-08 04:53 - 2014-11-23 12:10 - 00000000 _____ () C:\Windows\system32\newflow.dat
2014-11-08 04:53 - 2014-11-08 04:53 - 00000000 ____D () C:\Users\Public\OEM
2014-11-08 04:51 - 2014-11-08 04:51 - 00000000 ____D () C:\Users\karin\AppData\Local\AOP SDK
2014-11-08 04:50 - 2014-11-23 16:31 - 00000000 __RDO () C:\Users\karin\OneDrive
2014-11-08 04:50 - 2014-11-23 15:26 - 00002169 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
2014-11-08 04:50 - 2014-11-21 19:30 - 00002340 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-11-08 04:50 - 2014-11-21 19:15 - 00000000 ____D () C:\Users\karin\AppData\Local\clear.fi
2014-11-08 04:50 - 2014-11-08 04:50 - 00000000 ____D () C:\Users\karin\PicStream
2014-11-08 04:48 - 2014-11-23 17:24 - 00039521 _____ () C:\Users\karin\AppData\Local\BTServer.log
2014-11-08 04:48 - 2014-11-15 00:03 - 00000000 ____D () C:\Users\karin\AppData\Local\Packages
2014-11-08 04:48 - 2014-11-14 19:57 - 00000000 ____D () C:\Users\karin\AppData\Local\VirtualStore
2014-11-08 04:48 - 2014-11-08 04:48 - 00001458 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-08 04:48 - 2014-11-08 04:48 - 00001280 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2014-11-08 04:48 - 2014-11-08 04:48 - 00000180 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-11-08 04:48 - 2014-11-08 04:48 - 00000020 ___SH () C:\Users\karin\ntuser.ini
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Vorlagen
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Startmenü
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Netzwerkumgebung
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Lokale Einstellungen
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Eigene Dateien
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Druckumgebung
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Documents\Eigene Musik
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Documents\Eigene Bilder
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\AppData\Local\Verlauf
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\AppData\Local\Anwendungsdaten
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Anwendungsdaten
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Adobe
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Users\karin\AppData\Local\NVIDIA
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\ProgramData\OEM_YAHOO
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Program Files\Accessory Store
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Program Files (x86)\OEM
2014-11-08 04:47 - 2014-11-21 20:45 - 00000000 ____D () C:\Users\karin
2014-11-08 04:47 - 2014-08-14 22:37 - 00000000 ___RD () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-08 04:47 - 2014-03-18 11:33 - 00000000 ___RD () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-11-08 04:47 - 2014-03-18 11:13 - 00000369 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-11-08 04:47 - 2014-03-18 11:13 - 00000369 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-11-08 04:47 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-08 04:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Dokumente und Einstellungen
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-23 17:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2014-11-23 16:41 - 2014-08-14 13:10 - 01929095 _____ () C:\Windows\WindowsUpdate.log
2014-11-23 16:34 - 2014-08-14 22:31 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2014-11-23 16:34 - 2014-08-14 22:31 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2014-11-23 16:34 - 2014-03-18 11:03 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-23 16:30 - 2014-03-18 10:54 - 00031568 _____ () C:\Windows\PFRO.log
2014-11-23 16:30 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-23 16:29 - 2013-08-22 14:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-11-23 15:25 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PLA
2014-11-23 15:21 - 2013-08-22 14:25 - 00000226 _____ () C:\Windows\win.ini
2014-11-23 14:33 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-11-23 12:27 - 2014-08-14 13:46 - 00000000 ____D () C:\Windows\System32\Tasks\Recovery Management
2014-11-21 21:00 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-11-21 19:16 - 2014-06-11 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2014-11-21 19:16 - 2014-06-11 11:06 - 00000000 ____D () C:\Program Files (x86)\Acer
2014-11-21 19:15 - 2014-06-11 11:35 - 00000000 ___HD () C:\OEM
2014-11-20 15:19 - 2013-08-22 15:46 - 00024200 _____ () C:\Windows\setupact.log
2014-11-15 23:13 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-11-14 20:53 - 2014-06-11 11:19 - 00000000 ____D () C:\ProgramData\McAfee
2014-11-14 20:53 - 2013-08-22 15:44 - 00370496 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-14 20:51 - 2013-08-22 16:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-11-12 00:22 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\restore
2014-11-10 00:31 - 2014-06-11 11:06 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2014-11-09 18:49 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-08 05:01 - 2014-08-14 13:35 - 00000000 ____D () C:\ProgramData\OEM
2014-11-08 04:49 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-11-08 04:48 - 2014-06-11 11:42 - 00000000 ____D () C:\Windows\Panther
2014-11-08 03:08 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-11-08 03:07 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-11-08 03:07 - 2013-08-22 14:36 - 00000000 __RHD () C:\Users\Default
Some content of TEMP:
====================
C:\Users\karin\AppData\Local\Temp\HPInstaller.exe
C:\Users\karin\AppData\Local\Temp\ICReinstall_OpenOfficeSetup.exe
C:\Users\karin\AppData\Local\Temp\oct3521.tmp.exe
C:\Users\karin\AppData\Local\Temp\octD9A9.tmp.exe
C:\Users\karin\AppData\Local\Temp\optprosetup.exe
C:\Users\karin\AppData\Local\Temp\Quarantine.exe
C:\Users\karin\AppData\Local\Temp\sqlite3.dll
C:\Users\karin\AppData\Local\Temp\vosteranupdate.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-20 12:33
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
Hallo Schrauber,
hier kommt nun der Rest und ich hoffe, dass alles OK ist.
Werde nun meine Schutzsoftware wieder anstellen. Soll ich da gleich einen Durchlauf machen?
Erst einmal herzlichen Dank für Deine Unterstützung
mit lieben Gruß robertine
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-11-2014
Ran by karin (administrator) on KARINKOEPPEL on 23-11-2014 17:34:08
Running from C:\Users\karin\Desktop
Loaded Profile: karin (Available profiles: karin)
Platform: Windows 8.1 (Update 1) (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\ng\ngservice.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(RaMMicHaeL) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QASvc.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAEvent.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Spotify Ltd) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
() C:\Program Files (x86)\Acer\abDocs\abDocsDllLoaderMonitor.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerWinMonitor.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\RMSvc.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QAMsg.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Quick Access\QuickAccess.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(TODO: <Company name>) C:\Program Files\Acer\User Experience Improvement Program\Plugin\AppMonitor\AppMonitorPlugIn.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13672304 2014-03-21] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2199840 2014-03-26] (NVIDIA Corporation)
HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [217088 2014-06-06] (Realtek Semiconductor Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BacKGround Agent] => C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe [62208 2014-11-17] (Acer Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5226600 2014-11-21] (AVAST Software)
HKLM-x32\...\Run: [abDocsDllLoader] => C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe [90368 2014-11-20] ()
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\...\Run: [Spotify Web Helper] => C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1168896 2014-08-14] (Spotify Ltd)
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\...\Run: [HP Officejet 4620 series (NET)] => C:\Program Files\HP\HP Officejet 4620 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
Startup: C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series (Netzwerk).lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Officejet 4620 series.lnk
ShortcutTarget: Tintenwarnungen überwachen - HP Officejet 4620 series.lnk -> C:\Program Files\HP\HP Officejet 4620 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [ACloudSyncedRF] -> {5CCE71FA-9F61-4F24-9CD1-98D819B40D68} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncedSF] -> {5D5F18B7-D59B-4B18-A3E9-0A4BDCCCB699} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudSyncing] -> {C1E1456F-C2D8-4C96-870D-35F1E13941EE} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
ShellIconOverlayIdentifiers: [ACloudToBeSynced] -> {307523FA-DDC0-4068-983F-2A6B34627744} => C:\Program Files (x86)\Acer\Acer Portal\x64\shellext_win.dll (Acer Incorporated)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
HKU\S-1-5-21-2436487137-2019308104-1651275924-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/?pc=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Bar = http://www.msn.com/?pc=AV01
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKLM -> DefaultScope {772A39EF-A0CB-496E-9FD0-9C0494318335} URL =
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {772A39EF-A0CB-496E-9FD0-9C0494318335} URL = http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=ACJB
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = http://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-2436487137-2019308104-1651275924-1001 -> DefaultScope {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-2436487137-2019308104-1651275924-1001 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = http://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-2436487137-2019308104-1651275924-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\karin\AppData\Roaming\Mozilla\Firefox\Profiles\9z8u49j2.default
FF DefaultSearchUrl: hxxp://www.bing.com/search
FF SearchEngineOrder.1: Microsoft (Bing)
FF Homepage: hxxp://www.msn.com/?pc=AV01
FF Keyword.URL: hxxp://www.bing.com/search
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_223.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_223.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\karin\AppData\Roaming\Mozilla\Firefox\Profiles\9z8u49j2.default\searchplugins\bing-avast.xml
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-11-14]
FF Extension: No Name - wrc@avast.com [Not Found]
FF StartMenuInternet: FIREFOX.EXE - firefox.exe
Chrome:
=======
CHR Profile: C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-14]
CHR Extension: (Google Drive) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-14]
CHR Extension: (YouTube) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-14]
CHR Extension: (Google Search) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-14]
CHR Extension: (EnterDigital) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghpmlbobkefgcgihkmhnbkepebhfbamm [2014-11-18]
CHR Extension: (Avast Online Security) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-11-14]
CHR Extension: (Google Wallet) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-14]
CHR Extension: (Gmail) - C:\Users\karin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-14]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx []
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-21]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-11-21] (AVAST Software)
R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [4012248 2014-11-21] (Avast Software)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [94208 2014-05-06] () [File not signed]
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2709760 2014-11-17] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2573544 2014-03-21] (Acer Incorporated)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [254016 2014-10-07] (WildTangent)
R2 HPSLPSVC; C:\Users\karin\AppData\Local\Temp\7zS1C45\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-10] (Intel Corporation)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [459496 2014-03-17] (Acer Incorporate)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1616160 2014-03-26] (NVIDIA Corporation)
R3 QASvc; C:\Program Files\Acer\Acer Quick Access\QASvc.exe [457960 2014-03-21] (Acer Incorporate)
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [254512 2012-04-24] ()
R3 RMSvc; C:\Program Files\Acer\Acer Quick Access\RMSvc.exe [449768 2014-03-21] (Acer Incorporate)
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [222952 2014-01-24] (acer)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [111208 2014-11-14] (RaMMicHaeL)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [348392 2014-08-14] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-08-14] (Microsoft Corporation)
S2 McAfee SiteAdvisor Service; c:\PROGRA~2\mcafee\siteadvisor\mcsacore.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-11-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2014-11-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-11-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-11-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2014-11-23] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2014-11-21] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2014-11-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2014-11-21] ()
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
U5 GeneStor; C:\Windows\System32\Drivers\GeneStor.sys [111336 2014-04-28] (GenesysLogic)
R3 iaLPSS_GPIO; C:\Windows\System32\drivers\iaLPSS_GPIO.sys [24568 2013-10-03] (Intel Corporation)
R3 iaLPSS_I2C; C:\Windows\System32\drivers\iaLPSS_I2C.sys [99320 2013-10-03] (Intel Corporation)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-07-17] (Acer Incorporated)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2014-11-23] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-10-01] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-10] (Intel Corporation)
S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [14680 2013-07-17] (Acer Incorporated)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [573144 2014-04-18] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3468504 2014-05-22] (Realtek Semiconductor Corporation )
R3 SynRMIHID; C:\Windows\system32\DRIVERS\SynRMIHID.sys [42224 2014-02-20] (Synaptics Incorporated)
R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [271752 2014-11-21] (Avast Software)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [124760 2014-08-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-23 17:33 - 2014-11-23 17:33 - 00000000 ____D () C:\Users\karin\Desktop\FRST-OlderVersion
2014-11-23 17:27 - 2014-11-23 17:27 - 00000748 _____ () C:\Users\karin\Desktop\JRT.txt
2014-11-23 17:22 - 2014-11-23 17:22 - 00000000 ____D () C:\Windows\ERUNT
2014-11-23 17:12 - 2014-11-23 17:12 - 01707532 _____ (Thisisu) C:\Users\karin\Desktop\JRT.exe
2014-11-23 16:32 - 2014-11-23 16:32 - 00000197 _____ () C:\Windows\system32\2014-11-23-15-32-30.081-AvastVBoxSVC.exe-2964.log
2014-11-23 16:21 - 2014-11-23 16:21 - 00004997 _____ () C:\Users\karin\Desktop\AdwCleaner[S0].txt
2014-11-23 16:17 - 2014-11-23 16:43 - 00000000 ____D () C:\AdwCleaner
2014-11-23 16:11 - 2014-11-23 16:11 - 02140160 _____ () C:\Users\karin\Desktop\AdwCleaner_4.101.exe
2014-11-23 15:52 - 2014-11-23 15:52 - 00013992 _____ () C:\Users\karin\Desktop\mbam.txt
2014-11-23 15:27 - 2014-11-23 15:27 - 00000197 _____ () C:\Windows\system32\2014-11-23-14-27-47.012-AvastVBoxSVC.exe-2788.log
2014-11-23 15:11 - 2014-11-23 17:19 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-23 15:10 - 2014-11-23 15:10 - 00001122 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-23 15:10 - 2014-11-23 15:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-23 15:10 - 2014-11-23 15:10 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-23 15:10 - 2014-11-23 15:10 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-11-23 15:10 - 2014-10-01 11:11 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-23 15:10 - 2014-10-01 11:11 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-23 15:10 - 2014-10-01 11:11 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-23 15:02 - 2014-11-23 15:02 - 19828376 _____ (Malwarebytes Corporation ) C:\Users\karin\Downloads\mbam-setup-2.0.3.1025.exe
2014-11-23 14:44 - 2014-11-23 14:50 - 00001288 _____ () C:\Users\karin\Desktop\Revo Uninstaller.lnk
2014-11-23 14:44 - 2014-11-23 14:50 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-11-23 14:40 - 2014-11-23 14:40 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\karin\Downloads\revosetup95.exe
2014-11-21 20:44 - 2014-11-21 20:45 - 00000000 ____D () C:\Users\karin\Internet- Foren
2014-11-21 20:33 - 2014-11-23 17:34 - 00020513 _____ () C:\Users\karin\Desktop\FRST.txt
2014-11-21 20:33 - 2014-11-21 20:35 - 00035268 _____ () C:\Users\karin\Desktop\Addition.txt
2014-11-21 20:32 - 2014-11-23 17:34 - 00000000 ____D () C:\FRST
2014-11-21 20:27 - 2014-11-21 20:28 - 02117632 _____ (Farbar) C:\Users\karin\Downloads\FRST64(1).exe
2014-11-21 20:24 - 2014-11-23 17:33 - 02118144 _____ (Farbar) C:\Users\karin\Desktop\FRST64.exe
2014-11-21 19:56 - 2014-11-21 19:56 - 00000247 _____ () C:\Windows\system32\2014-11-21-18-56-22.023-aswFe.exe-11548.log
2014-11-21 19:46 - 2014-11-21 19:56 - 00000247 _____ () C:\Windows\system32\2014-11-21-18-46-39.093-aswFe.exe-3564.log
2014-11-21 19:46 - 2014-11-21 19:46 - 00000197 _____ () C:\Windows\system32\2014-11-21-18-46-30.070-AvastVBoxSVC.exe-3384.log
2014-11-21 19:21 - 2014-11-21 19:21 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-11-21 19:21 - 2014-11-21 19:21 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-11-20 17:33 - 2014-11-20 17:33 - 00000197 _____ () C:\Windows\system32\2014-11-20-16-33-32.051-AvastVBoxSVC.exe-2884.log
2014-11-20 17:31 - 2014-11-20 17:31 - 00000306 __RSH () C:\ProgramData\ntuser.pol
2014-11-20 12:27 - 2014-11-20 12:27 - 00000000 ____D () C:\Users\karin\Documents\My Bluetooth
2014-11-17 08:26 - 2014-11-21 00:00 - 00000000 ____D () C:\Users\karin\Documents\eigene Dokumente
2014-11-17 08:06 - 2014-11-17 08:08 - 00005632 ___SH () C:\Users\karin\Documents\Thumbs.db
2014-11-17 08:06 - 2014-11-17 08:06 - 00007334 _____ () C:\Users\karin\Documents\OpenDocument Text (neu).odt
2014-11-16 07:48 - 2014-11-16 07:48 - 00001141 _____ () C:\Users\karin\Desktop\Bilder - Verknüpfung.lnk
2014-11-16 06:41 - 2014-11-16 06:41 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-11-16 01:00 - 2014-11-16 01:00 - 00167997 _____ () C:\Users\karin\Documents\2014_09_lebens kosten-geändert_1.ods
2014-11-15 00:10 - 2014-11-18 16:06 - 00000000 ____D () C:\Users\karin\Documents\Finanzen
2014-11-15 00:04 - 2014-11-15 00:04 - 00001872 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\avast! antivirus.lnk
2014-11-14 23:13 - 2014-11-14 23:15 - 00000000 ____D () C:\Users\karin\Programme
2014-11-14 22:01 - 2014-11-14 22:01 - 00000247 _____ () C:\Windows\system32\2014-11-14-21-01-17.044-aswFe.exe-7492.log
2014-11-14 21:58 - 2014-11-14 22:01 - 00000247 _____ () C:\Windows\system32\2014-11-14-20-58-36.060-aswFe.exe-6532.log
2014-11-14 21:58 - 2014-11-14 21:58 - 00000197 _____ () C:\Windows\system32\2014-11-14-20-58-34.023-AvastVBoxSVC.exe-5192.log
2014-11-14 21:54 - 2014-11-14 21:54 - 00000000 ____D () C:\Windows\SysWOW64\vbox
2014-11-14 21:54 - 2014-11-14 21:54 - 00000000 ____D () C:\Windows\system32\vbox
2014-11-14 21:23 - 2014-11-14 21:23 - 00000000 ____D () C:\ProgramData\7bb6df21-8ca8-4eec-965d-8cd2261544c7
2014-11-14 21:13 - 2014-11-14 21:13 - 00000000 ____D () C:\Users\karin\AppData\Roaming\AVAST Software
2014-11-14 21:13 - 2014-11-14 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-11-14 21:13 - 2014-11-14 21:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2014-11-14 21:12 - 2014-11-23 17:17 - 00001134 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-14 21:12 - 2014-11-23 16:31 - 00001130 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-14 21:12 - 2014-11-23 15:28 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2014-11-14 21:12 - 2014-11-21 19:22 - 00003924 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-11-14 21:12 - 2014-11-21 19:21 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys
2014-11-14 21:12 - 2014-11-21 19:21 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys
2014-11-14 21:12 - 2014-11-14 21:13 - 00000000 ____D () C:\Users\karin\AppData\Local\Google
2014-11-14 21:12 - 2014-11-14 21:13 - 00000000 ____D () C:\Program Files (x86)\Google
2014-11-14 21:12 - 2014-11-14 21:12 - 00004106 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-11-14 21:12 - 2014-11-14 21:12 - 00003870 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-11-14 21:11 - 2014-11-14 21:11 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-11-14 21:11 - 2014-11-14 21:11 - 00000000 ____D () C:\Program Files\AVAST Software
2014-11-14 21:09 - 2014-11-14 21:10 - 131078000 _____ (AVAST Software) C:\Users\karin\Downloads\avast_free_antivirus_setup.exe
2014-11-14 21:08 - 2014-11-14 21:08 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Opera Software
2014-11-14 21:08 - 2014-11-14 21:08 - 00000000 ____D () C:\Users\karin\AppData\Local\Opera Software
2014-11-14 21:07 - 2014-11-21 19:15 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-11-14 21:07 - 2014-11-20 17:37 - 00003860 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1415995658
2014-11-14 21:07 - 2014-11-20 17:37 - 00001061 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2014-11-14 21:06 - 2014-11-14 21:06 - 00870264 _____ (Opera Software) C:\Users\karin\Downloads\Opera_NI_stable.exe
2014-11-14 20:26 - 2014-11-14 20:26 - 00000000 ____D () C:\Users\karin\AppData\Local\Macromedia
2014-11-14 20:24 - 2014-11-23 16:58 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-14 20:24 - 2014-11-20 12:58 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-11-14 20:24 - 2014-11-14 21:13 - 00000000 ____D () C:\Users\karin\AppData\Local\Adobe
2014-11-14 20:07 - 2014-11-14 20:07 - 00000000 ____D () C:\Users\karin\AppData\Roaming\OpenOffice
2014-11-14 20:05 - 2014-11-14 20:05 - 00000000 ___SD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-11-14 20:04 - 2014-11-14 23:35 - 00000000 ____D () C:\Program Files (x86)\OpenOffice 4
2014-11-14 19:56 - 2014-11-21 20:53 - 00000000 ____D () C:\Users\karin\AppData\Roaming\HpUpdate
2014-11-14 19:55 - 2014-11-14 19:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2014-11-14 19:55 - 2014-11-14 19:56 - 00000000 ____D () C:\Program Files (x86)\HP
2014-11-14 19:55 - 2014-11-14 19:55 - 00000057 _____ () C:\ProgramData\Ament.ini
2014-11-14 19:55 - 2014-11-14 19:55 - 00000000 ____D () C:\Program Files\HP
2014-11-14 19:55 - 2012-10-17 04:31 - 00741480 ____N (Hewlett-Packard Co.) C:\Windows\system32\HPDiscoPM6412.dll
2014-11-14 19:53 - 2014-11-14 19:56 - 00000000 ____D () C:\Users\karin\AppData\Local\HP
2014-11-14 19:49 - 2014-11-14 19:55 - 00000000 ____D () C:\ProgramData\HP
2014-11-14 19:49 - 2014-11-14 19:52 - 164858324 _____ () C:\Users\karin\Downloads\Apache_OpenOffice_4.1.1_Win_x86_install_de.exe
2014-11-14 19:46 - 2014-11-14 19:47 - 19904818 _____ () C:\Users\karin\Downloads\Apache_OpenOffice_4.1.1_Win_x86_langpack_de.exe
2014-11-14 19:39 - 2014-11-14 21:13 - 00000000 ____D () C:\ProgramData\Unchecky
2014-11-14 19:39 - 2014-11-14 19:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unchecky
2014-11-14 19:39 - 2014-11-14 19:39 - 00000000 ____D () C:\Program Files (x86)\Unchecky
2014-11-14 19:34 - 2014-11-14 19:34 - 02338824 _____ () C:\Users\karin\Downloads\hppiw.exe
2014-11-14 15:38 - 2014-11-14 15:38 - 00285810 ____T () C:\Users\karin\Documents\2014-11-14_Fritz-sichern-2.oxps
2014-11-14 15:34 - 2014-11-14 15:34 - 00284722 ____T () C:\Users\karin\Documents\2014-11-14_Fritz-sichern.oxps
2014-11-12 00:57 - 2014-11-12 00:57 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2014-11-11 14:32 - 2014-11-11 14:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-11-10 00:31 - 2014-11-10 00:31 - 00000000 ____D () C:\Users\karin\AppData\Roaming\WildTangent
2014-11-10 00:31 - 2014-11-10 00:31 - 00000000 ____D () C:\ProgramData\BlueStacks
2014-11-09 20:42 - 2014-11-09 20:42 - 00002118 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-11-09 20:42 - 2014-11-09 20:42 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Thunderbird
2014-11-09 20:42 - 2014-11-09 20:42 - 00000000 ____D () C:\Users\karin\AppData\Local\Thunderbird
2014-11-09 20:42 - 2014-11-09 20:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird
2014-11-09 20:23 - 2014-11-09 20:25 - 26315072 _____ (Mozilla) C:\Users\karin\Downloads\Thunderbird Setup 31.2.0.exe
2014-11-09 20:03 - 2014-11-14 21:14 - 00001155 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-09 20:03 - 2014-11-12 07:40 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-11-09 20:03 - 2014-11-09 20:13 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Mozilla
2014-11-09 20:03 - 2014-11-09 20:13 - 00000000 ____D () C:\Users\karin\AppData\Local\Mozilla
2014-11-09 20:03 - 2014-11-09 20:03 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-09 18:22 - 2014-11-11 14:12 - 00000000 ____D () C:\Users\karin\AppData\Local\Acer
2014-11-09 05:54 - 2014-11-23 17:31 - 00003946 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{0F5C2207-F544-488A-BB6D-D07B19818EA9}
2014-11-09 05:54 - 2014-11-09 05:54 - 00000000 __SHD () C:\Users\karin\AppData\Local\EmieUserList
2014-11-09 05:54 - 2014-11-09 05:54 - 00000000 __SHD () C:\Users\karin\AppData\Local\EmieSiteList
2014-11-09 05:54 - 2014-11-09 05:54 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Macromedia
2014-11-09 05:36 - 2014-11-20 20:52 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Spotify
2014-11-09 05:36 - 2014-11-09 05:36 - 00000000 ____D () C:\Users\karin\AppData\Local\Spotify
2014-11-09 05:35 - 2014-11-09 05:35 - 00000000 ____D () C:\Users\karin\AppData\Local\Acer Aspire R7 Tutorial
2014-11-09 05:25 - 2014-11-09 05:25 - 00000000 ____D () C:\Users\karin\AppData\Local\iGware
2014-11-08 05:21 - 2014-11-23 14:22 - 00000000 ____D () C:\Users\karin\AppData\Local\CrashDumps
2014-11-08 05:01 - 2014-11-08 05:01 - 00003334 _____ () C:\Windows\System32\Tasks\AcerCloud
2014-11-08 04:53 - 2014-11-23 16:36 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2436487137-2019308104-1651275924-1001
2014-11-08 04:53 - 2014-11-23 12:10 - 00000000 _____ () C:\Windows\system32\newflow.dat
2014-11-08 04:53 - 2014-11-08 04:53 - 00000000 ____D () C:\Users\Public\OEM
2014-11-08 04:51 - 2014-11-08 04:51 - 00000000 ____D () C:\Users\karin\AppData\Local\AOP SDK
2014-11-08 04:50 - 2014-11-23 16:31 - 00000000 __RDO () C:\Users\karin\OneDrive
2014-11-08 04:50 - 2014-11-23 15:26 - 00002169 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokki Start Menu.lnk
2014-11-08 04:50 - 2014-11-21 19:30 - 00002340 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2014-11-08 04:50 - 2014-11-21 19:15 - 00000000 ____D () C:\Users\karin\AppData\Local\clear.fi
2014-11-08 04:50 - 2014-11-08 04:50 - 00000000 ____D () C:\Users\karin\PicStream
2014-11-08 04:48 - 2014-11-23 17:24 - 00039521 _____ () C:\Users\karin\AppData\Local\BTServer.log
2014-11-08 04:48 - 2014-11-15 00:03 - 00000000 ____D () C:\Users\karin\AppData\Local\Packages
2014-11-08 04:48 - 2014-11-14 19:57 - 00000000 ____D () C:\Users\karin\AppData\Local\VirtualStore
2014-11-08 04:48 - 2014-11-08 04:48 - 00001458 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-08 04:48 - 2014-11-08 04:48 - 00001280 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HD Audio-Manager.lnk
2014-11-08 04:48 - 2014-11-08 04:48 - 00000180 _____ () C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-11-08 04:48 - 2014-11-08 04:48 - 00000020 ___SH () C:\Users\karin\ntuser.ini
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Vorlagen
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Startmenü
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Netzwerkumgebung
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Lokale Einstellungen
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Eigene Dateien
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Druckumgebung
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Documents\Eigene Musik
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Documents\Eigene Bilder
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\AppData\Local\Verlauf
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\AppData\Local\Anwendungsdaten
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 _SHDL () C:\Users\karin\Anwendungsdaten
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Adobe
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Users\karin\AppData\Local\NVIDIA
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\ProgramData\OEM_YAHOO
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Program Files\Accessory Store
2014-11-08 04:48 - 2014-11-08 04:48 - 00000000 ____D () C:\Program Files (x86)\OEM
2014-11-08 04:47 - 2014-11-21 20:45 - 00000000 ____D () C:\Users\karin
2014-11-08 04:47 - 2014-08-14 22:37 - 00000000 ___RD () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-11-08 04:47 - 2014-03-18 11:33 - 00000000 ___RD () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-11-08 04:47 - 2014-03-18 11:13 - 00000369 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2014-11-08 04:47 - 2014-03-18 11:13 - 00000369 _____ () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2014-11-08 04:47 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-08 04:47 - 2013-08-22 16:36 - 00000000 ____D () C:\Users\karin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Musik
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Public\Documents\Eigene Bilder
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Vorlagen
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Startmenü
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Netzwerkumgebung
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Lokale Einstellungen
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Eigene Dateien
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Druckumgebung
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Musik
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Documents\Eigene Bilder
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Verlauf
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\AppData\Local\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Musik
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\Documents\Eigene Bilder
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Verlauf
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Users\Default User\AppData\Local\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Vorlagen
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Startmenü
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Microsoft\Windows\Start Menu\Programme
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Dokumente
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\ProgramData\Anwendungsdaten
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Program Files\Gemeinsame Dateien
2014-11-08 03:07 - 2014-11-08 03:07 - 00000000 _SHDL () C:\Dokumente und Einstellungen
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-11-23 17:00 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\sru
2014-11-23 16:41 - 2014-08-14 13:10 - 01929095 _____ () C:\Windows\WindowsUpdate.log
2014-11-23 16:34 - 2014-08-14 22:31 - 00765582 _____ () C:\Windows\system32\perfh007.dat
2014-11-23 16:34 - 2014-08-14 22:31 - 00159366 _____ () C:\Windows\system32\perfc007.dat
2014-11-23 16:34 - 2014-03-18 11:03 - 01776918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-23 16:30 - 2014-03-18 10:54 - 00031568 _____ () C:\Windows\PFRO.log
2014-11-23 16:30 - 2013-08-22 15:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-23 16:29 - 2013-08-22 14:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2014-11-23 15:25 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\PLA
2014-11-23 15:21 - 2013-08-22 14:25 - 00000226 _____ () C:\Windows\win.ini
2014-11-23 14:33 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\AppReadiness
2014-11-23 12:27 - 2014-08-14 13:46 - 00000000 ____D () C:\Windows\System32\Tasks\Recovery Management
2014-11-21 21:00 - 2013-08-22 16:20 - 00000000 ____D () C:\Windows\CbsTemp
2014-11-21 19:16 - 2014-06-11 11:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2014-11-21 19:16 - 2014-06-11 11:06 - 00000000 ____D () C:\Program Files (x86)\Acer
2014-11-21 19:15 - 2014-06-11 11:35 - 00000000 ___HD () C:\OEM
2014-11-20 15:19 - 2013-08-22 15:46 - 00024200 _____ () C:\Windows\setupact.log
2014-11-15 23:13 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\GroupPolicy
2014-11-14 20:53 - 2014-06-11 11:19 - 00000000 ____D () C:\ProgramData\McAfee
2014-11-14 20:53 - 2013-08-22 15:44 - 00370496 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-14 20:51 - 2013-08-22 16:36 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-11-12 00:22 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\restore
2014-11-10 00:31 - 2014-06-11 11:06 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2014-11-09 18:49 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-08 05:01 - 2014-08-14 13:35 - 00000000 ____D () C:\ProgramData\OEM
2014-11-08 04:49 - 2013-08-22 14:25 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-11-08 04:48 - 2014-06-11 11:42 - 00000000 ____D () C:\Windows\Panther
2014-11-08 03:08 - 2013-08-22 16:36 - 00000000 ____D () C:\Windows\rescache
2014-11-08 03:07 - 2013-08-22 16:36 - 00000000 ____D () C:\Program Files\Windows NT
2014-11-08 03:07 - 2013-08-22 14:36 - 00000000 __RHD () C:\Users\Default
Some content of TEMP:
====================
C:\Users\karin\AppData\Local\Temp\HPInstaller.exe
C:\Users\karin\AppData\Local\Temp\ICReinstall_OpenOfficeSetup.exe
C:\Users\karin\AppData\Local\Temp\oct3521.tmp.exe
C:\Users\karin\AppData\Local\Temp\octD9A9.tmp.exe
C:\Users\karin\AppData\Local\Temp\optprosetup.exe
C:\Users\karin\AppData\Local\Temp\Quarantine.exe
C:\Users\karin\AppData\Local\Temp\sqlite3.dll
C:\Users\karin\AppData\Local\Temp\vosteranupdate.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-11-20 12:33
==================== End Of Log ============================ --- --- ---
--- --- --- |