x-taucher | 14.01.2015 12:00 | Antwort Teil1 Hallo Schrauber,
danke für Deine Hilfe!
anbei die JRT.txt Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.4.1 (12.28.2014:1)
OS: Windows 8.1 x64
Ran by Wolfgang Wangler on 14.01.2015 at 11:47:12,54
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted the following from C:\Users\Wolfgang Wangler\AppData\Roaming\mozilla\firefox\profiles\zfvab1d9.default-1418386945468\prefs.js
user_pref("extensions.FiwWRg6XkjHUiynv.url", "hxxp://fastgroupchinayour.net/sync2/?q=hfZ9oemRCzaMCyVUojwMg708BNmGWj8wmihGheDUojw8rdwFrTw5rjk8pihIC7n0rjkErjw9rjaFrHk7tNhVCT94tM
user_pref("extensions.Le7INyYaVMOMoZiV.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnale
user_pref("extensions.ccfUk0OGVdXTzaGG.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnale
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.01.2015 at 11:50:40,57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ die AdwCleaner.txt Code:
# AdwCleaner v4.107 - Bericht erstellt am 14/01/2015 um 11:41:12
# Aktualisiert 07/01/2015 von Xplode
# Database : 2015-01-13.2 [Live]
# Betriebssystem : Windows 8.1 (64 bits)
# Benutzername : Wolfgang Wangler - WANGLER-PC
# Gestartet von : C:\Users\Wolfgang Wangler\Downloads\AdwCleaner_4.107.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\dealpaeeaako
Ordner Gelöscht : C:\ProgramData\eaasytoshop
Ordner Gelöscht : C:\ProgramData\FineDEalSofto
Ordner Gelöscht : C:\ProgramData\SMoArtCompare
Ordner Gelöscht : C:\ProgramData\SSmartCompaarE
Ordner Gelöscht : C:\ProgramData\3df327fe1df48862
Ordner Gelöscht : C:\ProgramData\4463955628032034914
Ordner Gelöscht : C:\Program Files (x86)\Amazon\ABB
Ordner Gelöscht : C:\Users\WOLFGA~1\AppData\Local\Temp\Hold Page
Ordner Gelöscht : C:\Users\Wolfgang Wangler\Documents\Optimizer Pro
Datei Gelöscht : C:\Users\Wolfgang Wangler\AppData\Roaming\Mozilla\Firefox\Profiles\zfvab1d9.default-1418386945468\user.js
***** [ Tasks ] *****
Task Gelöscht : Optimizer Pro Schedule
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Classes\pokki
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com
Wert Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Pokki]
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P042519e6_9a75_494f_b3ce_2ba26ea3fca6_.P042519e6_9a75_494f_b3ce_2ba26ea3fca6_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P042519e6_9a75_494f_b3ce_2ba26ea3fca6_.P042519e6_9a75_494f_b3ce_2ba26ea3fca6_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\.
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\..9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P5201346f_3115_4cec_b64d_fe932ad53bcf_.P5201346f_3115_4cec_b64d_fe932ad53bcf_
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\P5201346f_3115_4cec_b64d_fe932ad53bcf_.P5201346f_3115_4cec_b64d_fe932ad53bcf_.9
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{042519e6-9a75-494f-b3ce-2ba26ea3fca6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{0a34e2b5-00c6-4d41-8500-965da7ed1db1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{5201346f-3115-4cec-b64d-fe932ad53bcf}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{042519e6-9a75-494f-b3ce-2ba26ea3fca6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5201346f-3115-4cec-b64d-fe932ad53bcf}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{042519e6-9a75-494f-b3ce-2ba26ea3fca6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5201346f-3115-4cec-b64d-fe932ad53bcf}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{042519e6-9a75-494f-b3ce-2ba26ea3fca6}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{5201346f-3115-4cec-b64d-fe932ad53bcf}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{042519e6-9a75-494f-b3ce-2ba26ea3fca6}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{0a34e2b5-00c6-4d41-8500-965da7ed1db1}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{5201346f-3115-4cec-b64d-fe932ad53bcf}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{042519e6-9a75-494f-b3ce-2ba26ea3fca6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{5201346f-3115-4cec-b64d-fe932ad53bcf}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{EAF749DC-CD87-4B04-B22A-D4AC3FBCB2BC}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{042519e6-9a75-494f-b3ce-2ba26ea3fca6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5201346f-3115-4cec-b64d-fe932ad53bcf}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{87D7A644-DF1B-4882-9D5D-A7EE14F9A300}
Schlüssel Gelöscht : HKCU\Software\Optimizer Pro
Schlüssel Gelöscht : HKCU\Software\Pokki
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\SOFTWARE\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
Schlüssel Gelöscht : HKLM\SOFTWARE\{6791A2F3-FC80-475C-A002-C014AF797E9C}
Schlüssel Gelöscht : HKLM\SOFTWARE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Pokki
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v34.0.5 (x86 de)
[zfvab1d9.default-1418386945468\prefs.js] - Zeile gelöscht : user_pref("extensions.CLYyaFwpdkrr4u3z.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[zfvab1d9.default-1418386945468\prefs.js] - Zeile gelöscht : user_pref("extensions.FiwWRg6XkjHUiynv.scode", "try{(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1url.indexOf(\"warnalert11.com\")>-1url.index[...]
[zfvab1d9.default-1418386945468\prefs.js] - Zeile gelöscht : user_pref("extensions.Le7INyYaVMOMoZiV.url", "hxxp://safesitte.com/sync2/?q=hfZ9oen9BihEAen0rihTB6lKDzt4okmxtNtVh7n0rjkErja8rjnEpda6tMFHhd9FqjaFrdkFqdw5rdYMDMlGojUMAe4Uojw9rHs5qdUGrTr8qds6pjw9qHU8tNqH[...]
*************************
AdwCleaner[R0].txt - [6957 octets] - [14/01/2015 11:38:33]
AdwCleaner[S0].txt - [6757 octets] - [14/01/2015 11:41:12]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [6817 octets] ########## die MBAM.txt Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 14.01.2015
Suchlauf-Zeit: 11:21:46
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.4.1028
Malware Datenbank: v2015.01.14.03
Rootkit Datenbank: v2015.01.07.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Wolfgang Wangler
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 384266
Verstrichene Zeit: 7 Min, 44 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 13
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{A9F7A981-09A3-C1F7-2D46-1BA20CFDF02F}, , [a8a3589f2c5d35011f32a140ff03ab55],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{3ac80483-9d65-47b1-b46d-b2280a3bd6c2}, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3AC80483-9D65-47B1-B46D-B2280A3BD6C2}, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{3AC80483-9D65-47B1-B46D-B2280A3BD6C2}, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_.P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_.P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_.9, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_.P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_.P3ac80483_9d65_47b1_b46d_b2280a3bd6c2_.9, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{3AC80483-9D65-47B1-B46D-B2280A3BD6C2}, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\CLASSES\CLSID\{3AC80483-9D65-47B1-B46D-B2280A3BD6C2}\INPROCSERVER32, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3AC80483-9D65-47B1-B46D-B2280A3BD6C2}, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{3AC80483-9D65-47B1-B46D-B2280A3BD6C2}, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.Multiplug, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{C60D3D4E-3B20-5AB3-7F2C-9C946AD4080F}, , [f5569d5abdccb383a2aff6eb47bb4cb4],
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 0
(Keine schädliche Elemente erkannt)
Dateien: 4
PUP.Optional.Multiplug, C:\ProgramData\SSmartCompaarE\aRAtkGlMccyXLc.exe, , [a8a3589f2c5d35011f32a140ff03ab55],
PUP.Optional.MultiPlug.A, C:\ProgramData\dealpaeeaako\STQ5qSyyslWPqL.dll, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.MultiPlug.A, C:\ProgramData\dealpaeeaako\STQ5qSyyslWPqL.x64.dll, , [4efd985ff297181e99d7d7af6f967a86],
PUP.Optional.Multiplug, C:\ProgramData\dealpaeeaako\STQ5qSyyslWPqL.exe, , [f5569d5abdccb383a2aff6eb47bb4cb4],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) FRST Teil1
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 07-01-2015
Ran by Wolfgang Wangler (administrator) on WANGLER-PC on 14-01-2015 11:57:32
Running from C:\Users\Wolfgang Wangler\Downloads
Loaded Profile: Wolfgang Wangler (Available profiles: Wolfgang Wangler & Administrator)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgfws.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Lenovo) C:\Windows\jmesoft\hotkey.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe
() C:\Windows\jmesoft\JME_LOAD.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcfgex.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\reader_sl.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM-x32\...\Run: [jmekey] => C:\WINDOWS\jmesoft\hotkey.exe [118784 2013-07-24] (Lenovo)
HKLM-x32\...\Run: [jmesoft] => C:\Windows\jmesoft\ServiceLoader.exe [28672 2011-08-16] ()
HKLM-x32\...\Run: [LVT] => C:\Program Files\Lenovo\LVT\LJYZ.exe [886112 2011-11-24] (Lenovo)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-08] (CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc.exe [103720 2009-12-04] (CyberLink)
HKLM-x32\...\Run: [UpdateP2GoShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [214312 2011-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguix.exe [1133584 2014-11-28] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3667472 2014-12-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-1535484509-1023557788-1269224655-1001\...\RunOnce: [Application Restart #1] => C:\Users\Wolfgang Wangler\AppData\Local\Pokki\Engine\HostAppService.exe [7843656 2015-01-01] (Pokki)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FamilySafetyGuide.lnk
ShortcutTarget: FamilySafetyGuide.lnk -> C:\Program Files\Lenovo\LenovoFamilySecurity\LenovoFamilySecurity.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1535484509-1023557788-1269224655-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1535484509-1023557788-1269224655-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo13.msn.com/?pc=LCJB
HKU\S-1-5-21-1535484509-1023557788-1269224655-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com
HKU\S-1-5-21-1535484509-1023557788-1269224655-1001\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1535484509-1023557788-1269224655-1001 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
BHO: SSmartCompaarE -> {11074f38-1888-42e8-9f87-e4ca8968cf81} -> C:\ProgramData\SSmartCompaarE\aRAtkGlMccyXLc.x64.dll No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Wolfgang Wangler\AppData\Roaming\Mozilla\Firefox\Profiles\zfvab1d9.default-1418386945468
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll (Nitro PDF)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Wolfgang Wangler\AppData\Roaming\Mozilla\Firefox\Profiles\zfvab1d9.default-1418386945468\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-01-05]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-05-26]
FF HKU\S-1-5-21-1535484509-1023557788-1269224655-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - No Path
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 10c3b81e; c:\Program Files (x86)\LinkInstance\LinkInstance.dll [2139136 2015-01-12] () [File not signed]
R2 avgfws; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [1486664 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3432976 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [858640 2014-11-28] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [298080 2014-12-18] (AVG Technologies CZ, s.r.o.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-03] (Intel Corporation)
S2 JME Keyboard; C:\Windows\jmesoft\Service.exe [32768 2011-08-16] () [File not signed]
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\mcafee\ActWiz\McAWFwk.exe [334608 2013-07-29] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-09-04] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2014-04-28] (Hewlett-Packard) [File not signed]
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-12] (Nitro PDF Software)
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2014-04-28] (Hewlett-Packard) [File not signed]
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2013-05-14] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [153368 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [260888 2014-12-08] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [203544 2014-11-18] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [243480 2014-08-28] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [313624 2014-07-18] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [124184 2014-10-05] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-18] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [277784 2014-09-24] (AVG Technologies CZ, s.r.o.)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100824 2013-12-03] (Intel Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [445512 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-08-20] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3344352 2013-07-08] (Intel Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-13] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-14 11:50 - 2015-01-14 11:50 - 00001327 _____ () C:\Users\Wolfgang Wangler\Desktop\JRT.txt
2015-01-14 11:47 - 2015-01-14 11:47 - 00000000 ____D () C:\WINDOWS\ERUNT
2015-01-14 11:47 - 2015-01-14 11:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-01-14 11:46 - 2015-01-14 11:46 - 01707939 _____ (Thisisu) C:\Users\Wolfgang Wangler\Downloads\JRT.exe
2015-01-14 11:38 - 2015-01-14 11:41 - 00000000 ____D () C:\AdwCleaner
2015-01-14 11:31 - 2015-01-14 11:31 - 00003788 _____ () C:\Users\Wolfgang Wangler\Desktop\mbam.txt
2015-01-12 18:47 - 2015-01-12 18:47 - 00000000 __SHD () C:\Users\Wolfgang Wangler\AppData\Local\EmieUserList
2015-01-12 18:47 - 2015-01-12 18:47 - 00000000 __SHD () C:\Users\Wolfgang Wangler\AppData\Local\EmieSiteList
2015-01-12 18:47 - 2015-01-12 18:47 - 00000000 __SHD () C:\Users\Wolfgang Wangler\AppData\Local\EmieBrowserModeList
2015-01-12 15:53 - 2015-01-14 11:21 - 00129752 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-01-12 15:52 - 2015-01-12 15:52 - 00001129 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-01-12 15:52 - 2015-01-12 15:52 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-01-12 15:52 - 2015-01-12 15:52 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-01-12 15:52 - 2015-01-12 15:52 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-01-12 15:52 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-01-12 15:52 - 2014-11-21 06:14 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-01-12 15:52 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-01-12 15:40 - 2015-01-12 15:40 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\Wolfgang Wangler\Downloads\mbam-setup-2.0.4.1028.exe
2015-01-12 15:40 - 2015-01-12 15:40 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Wolfgang Wangler\Downloads\revosetup95.exe
2015-01-12 15:40 - 2015-01-12 15:40 - 02191360 _____ () C:\Users\Wolfgang Wangler\Downloads\AdwCleaner_4.107.exe
2015-01-12 10:58 - 2015-01-12 10:58 - 00000000 ____D () C:\Program Files (x86)\LinkInstance
2015-01-08 17:36 - 2015-01-08 17:36 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Roaming\LSC
2015-01-08 17:16 - 2015-01-08 17:16 - 01376768 _____ () C:\Users\Wolfgang Wangler\Downloads\7z920-x64.msi
2015-01-08 17:16 - 2015-01-08 17:16 - 00023890 _____ () C:\Users\Wolfgang Wangler\Downloads\FRST.zip
2015-01-08 17:16 - 2015-01-08 17:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-01-08 17:16 - 2015-01-08 17:16 - 00000000 ____D () C:\Program Files\7-Zip
2015-01-08 16:32 - 2015-01-08 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2015-01-08 16:32 - 2015-01-08 16:32 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2015-01-08 14:51 - 2015-01-08 14:51 - 00014035 _____ () C:\Users\Wolfgang Wangler\Downloads\Gmer.log
2015-01-08 14:15 - 2015-01-08 14:16 - 00028447 _____ () C:\Users\Wolfgang Wangler\Downloads\Addition.txt
2015-01-08 14:13 - 2015-01-14 11:57 - 00017489 _____ () C:\Users\Wolfgang Wangler\Downloads\FRST.txt
2015-01-08 14:13 - 2015-01-14 11:57 - 00000000 ____D () C:\FRST
2015-01-08 14:12 - 2015-01-08 14:12 - 00000494 _____ () C:\Users\Wolfgang Wangler\Downloads\defogger_disable.log
2015-01-08 14:12 - 2015-01-08 14:12 - 00000000 _____ () C:\Users\Wolfgang Wangler\defogger_reenable
2015-01-08 14:10 - 2015-01-08 14:10 - 02124288 _____ (Farbar) C:\Users\Wolfgang Wangler\Downloads\FRST64.exe
2015-01-08 14:10 - 2015-01-08 14:10 - 00380416 _____ () C:\Users\Wolfgang Wangler\Downloads\Gmer-19357.exe
2015-01-08 14:04 - 2015-01-08 14:06 - 00050477 _____ () C:\Users\Wolfgang Wangler\Downloads\Defogger.exe
2015-01-08 13:35 - 2015-01-08 16:32 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Roaming\Apple Computer
2015-01-08 13:35 - 2015-01-08 13:35 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\Apple Computer
2015-01-08 13:34 - 2015-01-08 13:34 - 00001806 _____ () C:\Users\Public\Desktop\iTunes.lnk
2015-01-08 13:34 - 2015-01-08 13:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-01-08 13:33 - 2015-01-08 13:33 - 00000000 ____D () C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2015-01-08 13:33 - 2015-01-08 13:33 - 00000000 ____D () C:\ProgramData\Apple Computer
2015-01-08 13:33 - 2015-01-08 13:33 - 00000000 ____D () C:\Program Files\iTunes
2015-01-08 13:33 - 2015-01-08 13:33 - 00000000 ____D () C:\Program Files\iPod
2015-01-08 13:33 - 2015-01-08 13:33 - 00000000 ____D () C:\Program Files (x86)\iTunes
2015-01-08 13:33 - 2012-10-03 16:14 - 00033240 _____ (GEAR Software Inc.) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
2015-01-08 13:31 - 2015-01-08 13:31 - 00002535 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-01-08 13:31 - 2015-01-08 13:31 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_Kernel_netaapl64_01009.Wdf
2015-01-08 13:31 - 2015-01-08 13:31 - 00000000 ____D () C:\WINDOWS\System32\Tasks\Apple
2015-01-08 13:31 - 2015-01-08 13:31 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\Apple
2015-01-08 13:31 - 2015-01-08 13:31 - 00000000 ____D () C:\Program Files (x86)\Apple Software Update
2015-01-08 13:29 - 2015-01-08 13:33 - 00000000 ____D () C:\Program Files\Common Files\Apple
2015-01-08 13:29 - 2015-01-08 13:31 - 00000000 ____D () C:\ProgramData\Apple
2015-01-08 13:29 - 2015-01-08 13:29 - 00000000 ____D () C:\Program Files\Bonjour
2015-01-08 13:29 - 2015-01-08 13:29 - 00000000 ____D () C:\Program Files (x86)\Bonjour
2015-01-08 13:26 - 2015-01-08 13:28 - 122418480 _____ (Apple Inc.) C:\Users\Wolfgang Wangler\Downloads\iTunes64Setup.exe
2015-01-07 09:36 - 2015-01-14 11:47 - 00001871 _____ () C:\Users\Public\Desktop\McAfee LiveSafe – Internet Security.lnk
2015-01-05 16:39 - 2015-01-12 15:41 - 00001295 _____ () C:\Users\Wolfgang Wangler\Desktop\Revo Uninstaller.lnk
2015-01-05 16:39 - 2015-01-12 15:41 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-01-05 16:38 - 2015-01-05 16:39 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Wolfgang Wangler\Downloads\revosetup.exe
2015-01-05 16:32 - 2015-01-05 16:32 - 00000000 ____D () C:\Users\Default\AppData\Roaming\TuneUp Software
2015-01-05 14:11 - 2015-01-05 14:11 - 00000000 ____D () C:\Users\Default\AppData\Local\Microsoft Help
2015-01-05 13:55 - 2014-07-24 16:28 - 00419648 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-01-05 13:55 - 2014-07-24 16:28 - 00412992 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2015-01-05 13:55 - 2014-07-24 16:28 - 00280384 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-01-05 13:55 - 2014-07-24 16:28 - 00143680 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2015-01-05 13:55 - 2014-07-24 16:25 - 00054752 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-01-05 13:55 - 2014-07-24 16:23 - 00125472 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-01-05 13:55 - 2014-07-24 16:20 - 00645592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2015-01-05 13:55 - 2014-07-24 16:20 - 00263400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-01-05 13:55 - 2014-07-24 16:16 - 02574208 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2015-01-05 13:55 - 2014-07-24 16:16 - 00211216 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVol.exe
2015-01-05 13:55 - 2014-07-24 16:07 - 02009920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-01-05 13:55 - 2014-07-24 16:05 - 01660048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-01-05 13:55 - 2014-07-24 16:05 - 01519560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-01-05 13:55 - 2014-07-24 16:05 - 01488008 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-01-05 13:55 - 2014-07-24 16:05 - 01356840 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-01-05 13:55 - 2014-07-24 16:03 - 02141920 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-01-05 13:55 - 2014-07-24 16:03 - 00882136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-01-05 13:55 - 2014-07-24 16:03 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2015-01-05 13:55 - 2014-07-24 16:03 - 00233888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-01-05 13:55 - 2014-07-24 16:03 - 00205512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2015-01-05 13:55 - 2014-07-24 14:50 - 00098048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-01-05 13:55 - 2014-07-24 14:48 - 02410976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2015-01-05 13:55 - 2014-07-24 14:48 - 00180208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVol.exe
2015-01-05 13:55 - 2014-07-24 14:46 - 00477200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2015-01-05 13:55 - 2014-07-24 14:36 - 02145472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-01-05 13:55 - 2014-07-24 14:36 - 00707536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-01-05 13:55 - 2014-07-24 14:36 - 00355800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2015-01-05 13:55 - 2014-07-24 14:36 - 00180720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2015-01-05 13:55 - 2014-07-24 12:51 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRUM.DLL
2015-01-05 13:55 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDYAK.DLL
2015-01-05 13:55 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDTT102.DLL
2015-01-05 13:55 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDTAT.DLL
2015-01-05 13:55 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRU1.DLL
2015-01-05 13:55 - 2014-07-24 12:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDBASH.DLL
2015-01-05 13:55 - 2014-07-24 12:51 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDRU.DLL
2015-01-05 13:55 - 2014-07-24 12:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\IPMIDrv.sys
2015-01-05 13:55 - 2014-07-24 12:45 - 00076800 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2015-01-05 13:55 - 2014-07-24 12:44 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2015-01-05 13:55 - 2014-07-24 12:43 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2015-01-05 13:55 - 2014-07-24 12:42 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2015-01-05 13:55 - 2014-07-24 12:42 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NdisImPlatform.sys FRST Teil2 Code:
2015-01-05 13:55 - 2014-07-24 12:33 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-01-05 13:55 - 2014-07-24 12:33 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-01-05 13:55 - 2014-07-24 12:06 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\iasnap.dll
2015-01-05 13:55 - 2014-07-24 12:05 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2015-01-05 13:55 - 2014-07-24 12:05 - 00226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebClnt.dll
2015-01-05 13:55 - 2014-07-24 11:52 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDYAK.DLL
2015-01-05 13:55 - 2014-07-24 11:52 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDTT102.DLL
2015-01-05 13:55 - 2014-07-24 11:52 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDTAT.DLL
2015-01-05 13:55 - 2014-07-24 11:51 - 00008192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRUM.DLL
2015-01-05 13:55 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRU1.DLL
2015-01-05 13:55 - 2014-07-24 11:51 - 00007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDBASH.DLL
2015-01-05 13:55 - 2014-07-24 11:51 - 00006656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDRU.DLL
2015-01-05 13:55 - 2014-07-24 11:49 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersGPExt.dll
2015-01-05 13:55 - 2014-07-24 11:33 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-01-05 13:55 - 2014-07-24 11:32 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.cpl
2015-01-05 13:55 - 2014-07-24 11:20 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-01-05 13:55 - 2014-07-24 11:18 - 01089024 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpedit.dll
2015-01-05 13:55 - 2014-07-24 11:12 - 00878592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-01-05 13:55 - 2014-07-24 11:10 - 01844224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Display.dll
2015-01-05 13:55 - 2014-07-24 11:10 - 00834560 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2015-01-05 13:55 - 2014-07-24 11:10 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WebClnt.dll
2015-01-05 13:55 - 2014-07-24 11:10 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iasnap.dll
2015-01-05 13:55 - 2014-07-24 11:05 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2015-01-05 13:55 - 2014-07-24 10:52 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-01-05 13:55 - 2014-07-24 10:44 - 16874496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-01-05 13:55 - 2014-07-24 10:42 - 00206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\powercfg.cpl
2015-01-05 13:55 - 2014-07-24 10:40 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs.dll
2015-01-05 13:55 - 2014-07-24 10:39 - 00770048 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2015-01-05 13:55 - 2014-07-24 10:33 - 01741824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-01-05 13:55 - 2014-07-24 10:32 - 01048064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gpedit.dll
2015-01-05 13:55 - 2014-07-24 10:27 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2015-01-05 13:55 - 2014-07-24 10:25 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-01-05 13:55 - 2014-07-24 10:24 - 01817088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Display.dll
2015-01-05 13:55 - 2014-07-24 10:21 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser.dll
2015-01-05 13:55 - 2014-07-24 10:18 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2015-01-05 13:55 - 2014-07-24 10:16 - 12730880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-01-05 13:55 - 2014-07-24 10:14 - 00443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2015-01-05 13:55 - 2014-07-24 10:12 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2015-01-05 13:55 - 2014-07-24 10:11 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\conhost.exe
2015-01-05 13:55 - 2014-07-24 10:11 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
2015-01-05 13:55 - 2014-07-24 10:10 - 00540672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-01-05 13:55 - 2014-07-24 10:04 - 00492032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintDialogs.dll
2015-01-05 13:55 - 2014-07-24 10:04 - 00183808 _____ (Microsoft Corp.) C:\WINDOWS\system32\Defrag.exe
2015-01-05 13:55 - 2014-07-24 10:03 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\srvsvc.dll
2015-01-05 13:55 - 2014-07-24 10:02 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-01-05 13:55 - 2014-07-24 09:58 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2015-01-05 13:55 - 2014-07-24 09:53 - 01261056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gpsvc.dll
2015-01-05 13:55 - 2014-07-24 09:53 - 00449536 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2015-01-05 13:55 - 2014-07-24 09:49 - 01287680 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2015-01-05 13:55 - 2014-07-24 09:49 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2015-01-05 13:55 - 2014-07-24 09:48 - 00659968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-01-05 13:55 - 2014-07-24 09:47 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-01-05 13:55 - 2014-07-24 09:43 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
2015-01-05 13:55 - 2014-07-24 09:39 - 02397184 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2015-01-05 13:55 - 2014-07-24 09:38 - 00371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2015-01-05 13:55 - 2014-07-24 09:36 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2015-01-05 13:55 - 2014-07-24 09:32 - 01532416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-01-05 13:55 - 2014-07-24 09:30 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2015-01-05 13:55 - 2014-07-24 09:29 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-01-05 13:55 - 2014-07-24 09:28 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2015-01-05 13:55 - 2014-07-24 09:23 - 01404416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2015-01-05 13:55 - 2014-07-24 09:22 - 00487936 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-01-05 13:55 - 2014-07-24 09:21 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-01-05 13:55 - 2014-07-24 09:21 - 00302080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2015-01-05 13:55 - 2014-07-24 09:19 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-01-05 13:55 - 2014-07-24 09:18 - 01144320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-01-05 13:55 - 2014-07-24 09:18 - 00795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2015-01-05 13:55 - 2014-07-24 09:18 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-01-05 13:55 - 2014-07-24 09:16 - 00505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2015-01-05 13:55 - 2014-07-24 09:16 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2015-01-05 13:55 - 2014-07-24 09:15 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-01-05 13:55 - 2014-07-24 09:15 - 00721408 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2015-01-05 13:55 - 2014-07-24 09:15 - 00432128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.dll
2015-01-05 13:55 - 2014-07-24 09:13 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2015-01-05 13:55 - 2014-07-24 09:10 - 00889344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-01-05 13:55 - 2014-07-24 09:10 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-01-05 13:55 - 2014-07-24 09:08 - 00321536 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-01-05 13:55 - 2014-07-24 09:07 - 01705472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-01-05 13:55 - 2014-07-24 09:06 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-01-05 13:55 - 2014-07-24 09:05 - 00448000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll
2015-01-05 13:55 - 2014-07-24 09:04 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-01-05 13:55 - 2014-07-24 09:02 - 03465216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-01-05 13:55 - 2014-07-24 09:01 - 01992192 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2015-01-05 13:55 - 2014-07-24 09:00 - 02100736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-01-05 13:55 - 2014-07-24 08:58 - 00432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-01-05 13:55 - 2014-07-24 08:58 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-01-05 13:55 - 2014-07-24 08:54 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2015-01-05 13:55 - 2014-07-24 08:50 - 01182208 _____ (Microsoft Corporation) C:\WINDOWS\system32\printui.dll
2015-01-05 13:55 - 2014-07-24 08:47 - 00576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-01-05 13:55 - 2014-07-24 08:44 - 01057792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\printui.dll
2015-01-05 13:55 - 2014-07-24 08:41 - 00459264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-01-05 13:55 - 2014-07-24 08:28 - 01600000 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-01-05 13:55 - 2014-07-24 05:11 - 00513544 _____ () C:\WINDOWS\SysWOW64\locale.nls
2015-01-05 13:55 - 2014-07-24 05:11 - 00513544 _____ () C:\WINDOWS\system32\locale.nls
2015-01-05 13:55 - 2014-07-12 06:55 - 00268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll
2015-01-05 13:55 - 2014-07-12 05:58 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
2015-01-05 13:55 - 2014-07-04 13:59 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2015-01-05 13:55 - 2014-07-04 11:29 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2015-01-05 13:55 - 2014-07-04 11:20 - 01656832 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2015-01-05 13:55 - 2014-07-04 11:06 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2015-01-05 13:55 - 2014-07-04 11:00 - 01351168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2015-01-05 13:55 - 2014-07-04 10:30 - 00544768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2015-01-05 13:55 - 2014-07-04 10:27 - 00474112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2015-01-05 13:55 - 2014-06-27 07:22 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2015-01-05 13:55 - 2014-06-26 01:32 - 01029632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2015-01-05 13:55 - 2014-06-26 01:29 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
2015-01-05 13:55 - 2014-06-20 00:37 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2015-01-05 13:55 - 2014-06-19 03:13 - 00310080 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2015-01-05 13:55 - 2014-06-14 07:03 - 02389504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2015-01-05 13:55 - 2014-06-14 06:46 - 02071552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2015-01-05 13:55 - 2014-06-07 13:46 - 00216368 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2015-01-05 13:55 - 2014-06-07 11:20 - 00189016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2015-01-05 13:55 - 2014-06-05 15:00 - 01118040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-01-05 13:55 - 2014-06-05 11:18 - 01018368 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2015-01-05 13:55 - 2014-06-05 10:42 - 00889856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2015-01-05 13:55 - 2014-05-31 06:00 - 01463808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2015-01-05 13:55 - 2014-05-31 05:18 - 01319936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2015-01-05 13:55 - 2014-05-29 07:23 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2015-01-05 13:55 - 2014-05-29 06:25 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2015-01-05 13:55 - 2014-05-26 08:26 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-01-05 13:55 - 2014-05-10 11:12 - 00387896 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2015-01-05 13:55 - 2014-05-10 09:46 - 00335680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2015-01-05 13:55 - 2014-05-06 05:41 - 00486744 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcfgx.dll
2015-01-05 13:55 - 2014-05-06 01:55 - 00391000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcfgx.dll
2015-01-05 13:55 - 2014-03-25 03:27 - 00160600 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmmbase.dll
2015-01-05 13:55 - 2014-03-25 03:27 - 00123920 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmm.dll
2015-01-05 13:55 - 2014-03-25 02:20 - 00128568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmm.dll
2015-01-05 13:55 - 2014-03-25 02:20 - 00127544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmmbase.dll
2015-01-05 13:33 - 2015-01-05 13:33 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Roaming\AVG2015
2015-01-05 13:32 - 2015-01-05 16:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-01-05 13:32 - 2015-01-05 15:27 - 00000000 ____D () C:\ProgramData\AVG2015
2015-01-05 13:32 - 2015-01-05 13:32 - 00000000 ___HD () C:\$AVG
2015-01-05 13:32 - 2015-01-05 13:32 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Roaming\TuneUp Software
2015-01-05 13:30 - 2015-01-14 11:42 - 00000000 ____D () C:\ProgramData\MFAData
2015-01-05 13:30 - 2015-01-05 15:10 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\Avg2015
2015-01-05 13:30 - 2015-01-05 13:30 - 00000958 _____ () C:\Users\Public\Desktop\AVG.lnk
2015-01-05 13:30 - 2015-01-05 13:30 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\MFAData
2015-01-05 13:30 - 2015-01-05 13:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG Zen
2015-01-05 13:29 - 2015-01-05 13:32 - 00000000 ____D () C:\Program Files (x86)\AVG
2015-01-05 13:29 - 2015-01-05 13:30 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\AvgSetupLog
2015-01-05 13:29 - 2015-01-05 13:30 - 00000000 ____D () C:\ProgramData\Avg
2015-01-05 13:29 - 2015-01-05 13:29 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\Avg
2015-01-05 13:28 - 2015-01-05 13:29 - 16634456 _____ (AVG Technologies) C:\Users\Wolfgang Wangler\Downloads\avg_gsr_stb_all_445p1_146.exe
2015-01-05 11:30 - 2015-01-05 11:30 - 00003886 _____ () C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2014-12-23 13:50 - 2014-12-23 13:50 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2014-12-17 17:55 - 2014-12-17 17:55 - 00022528 _____ () C:\Users\Wolfgang Wangler\AppData\Local\dsisetup1812535932.exe
2014-12-15 16:35 - 2014-12-15 16:35 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
2014-12-15 10:21 - 2014-10-30 23:37 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2014-12-15 10:21 - 2014-10-30 23:34 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2014-12-15 10:19 - 2014-08-15 01:36 - 00146752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2014-12-15 10:19 - 2014-07-30 02:56 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2014-12-15 10:19 - 2014-07-29 06:22 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcpmon.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-01-14 11:53 - 2014-12-08 16:41 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1535484509-1023557788-1269224655-1001
2015-01-14 11:46 - 2014-05-26 14:58 - 00765378 _____ () C:\WINDOWS\system32\perfh007.dat
2015-01-14 11:46 - 2014-05-26 14:58 - 00159696 _____ () C:\WINDOWS\system32\perfc007.dat
2015-01-14 11:46 - 2013-08-31 16:40 - 01780340 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-01-14 11:42 - 2013-08-31 16:36 - 00034348 _____ () C:\WINDOWS\PFRO.log
2015-01-14 11:42 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-01-14 11:42 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2015-01-14 11:41 - 2014-05-26 05:25 - 00000000 ____D () C:\Program Files (x86)\Amazon
2015-01-14 11:32 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-01-14 11:32 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2015-01-14 11:31 - 2014-05-26 05:30 - 01751177 _____ () C:\WINDOWS\WindowsUpdate.log
2015-01-14 11:25 - 2014-12-09 15:26 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-01-14 11:12 - 2013-08-22 16:20 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-01-14 11:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-01-14 10:25 - 2014-12-09 15:26 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-01-14 09:56 - 2014-12-08 16:30 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\Pokki
2015-01-12 16:12 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\DesktopTileResources
2015-01-12 15:50 - 2014-12-08 16:55 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Roaming\1H1Q1V0B1L1G1N1V0M1P1Q1L1T0D1P1E2Z
2015-01-12 11:55 - 2014-12-08 17:55 - 00000163 _____ () C:\Users\Wolfgang Wangler\AppData\Roaming\WB.CFG
2015-01-09 14:05 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-01-08 17:36 - 2014-12-08 16:32 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Roaming\Adobe
2015-01-08 16:32 - 2014-12-09 15:26 - 00001958 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2015-01-08 16:32 - 2014-12-09 15:26 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2015-01-08 15:12 - 2013-08-22 15:44 - 00492368 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-01-08 15:08 - 2013-08-22 20:12 - 00000000 ____D () C:\Program Files\Windows Journal
2015-01-08 15:08 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-01-08 15:08 - 2013-08-22 16:36 - 00000000 ___RD () C:\WINDOWS\ImmersiveControlPanel
2015-01-08 15:08 - 2013-08-22 16:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-01-08 15:08 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\setup
2015-01-08 15:08 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\InputMethod
2015-01-08 15:08 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\setup
2015-01-08 15:08 - 2013-08-22 14:36 - 00000000 ____D () C:\WINDOWS\system32\oobe
2015-01-08 14:19 - 2014-11-20 18:10 - 00000000 ____D () C:\Users\Wolfgang Wangler\.compeople
2015-01-08 14:12 - 2014-12-08 16:30 - 00000000 ____D () C:\Users\Wolfgang Wangler
2015-01-08 13:31 - 2013-08-22 15:46 - 00033457 _____ () C:\WINDOWS\setupact.log
2015-01-07 09:52 - 2014-12-12 14:59 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-07 09:45 - 2013-08-22 14:25 - 00000301 _____ () C:\WINDOWS\win.ini
2015-01-05 17:03 - 2014-05-26 05:28 - 00000000 ____D () C:\Program Files (x86)\Lenovo DE
2015-01-05 16:46 - 2014-12-10 18:55 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Roaming\Skype
2015-01-05 16:46 - 2014-12-10 11:14 - 00000000 ____D () C:\ProgramData\Skype
2015-01-05 13:32 - 2013-08-22 16:36 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2015-01-05 13:25 - 2014-12-08 17:07 - 00000000 ____D () C:\Users\Wolfgang Wangler\AppData\Local\Adobe
2015-01-05 13:20 - 2014-12-08 16:36 - 00002316 _____ () C:\Users\Wolfgang Wangler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-01-05 13:18 - 2014-12-08 17:09 - 00002457 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-01-05 13:18 - 2014-12-08 17:09 - 00002050 _____ () C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-01-05 13:18 - 2014-05-26 05:29 - 00000000 ____D () C:\ProgramData\Adobe
2015-01-05 11:31 - 2014-12-09 19:35 - 00002145 _____ () C:\Users\Wolfgang Wangler\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startmenü.lnk
2015-01-05 11:28 - 2014-05-26 05:24 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-12-17 17:55 - 2014-12-10 11:55 - 00000001 _____ () C:\Users\Wolfgang Wangler\AppData\Local\DSI.DAT
2014-12-15 15:35 - 2013-08-22 07:57 - 00000000 _____ () C:\WINDOWS\system32\connectedsearch-music.searchconnector-ms
Some content of TEMP:
====================
C:\Users\Wolfgang Wangler\AppData\Local\Temp\jna2014662916302116587.hunspell-win-x86-32.dll
C:\Users\Wolfgang Wangler\AppData\Local\Temp\jna7143538481878278443.hunspell-win-x86-32.dll
C:\Users\Wolfgang Wangler\AppData\Local\Temp\jna7742699024416276345.hunspell-win-x86-32.dll
C:\Users\Wolfgang Wangler\AppData\Local\Temp\oct5121.tmp.exe
C:\Users\Wolfgang Wangler\AppData\Local\Temp\oct89D8.tmp.exe
C:\Users\Wolfgang Wangler\AppData\Local\Temp\optprosetup.exe
C:\Users\Wolfgang Wangler\AppData\Local\Temp\ose00000.exe
C:\Users\Wolfgang Wangler\AppData\Local\Temp\Quarantine.exe
C:\Users\Wolfgang Wangler\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Wolfgang Wangler\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-01-13 17:39
==================== End Of Log ============================ --- --- --- |