Johannes K | 09.04.2015 17:18 | Okay hab alles gemacht: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Protection, 09.04.2015 13:10:07, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Starting,
Protection, 09.04.2015 13:10:07, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Started,
Protection, 09.04.2015 13:10:07, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Starting,
Protection, 09.04.2015 13:10:07, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Started,
Update, 09.04.2015 13:10:23, SYSTEM, JOHANNES-PC, Manual, Rootkit Database, 2015.2.25.1, 2015.3.31.1,
Update, 09.04.2015 13:10:26, SYSTEM, JOHANNES-PC, Manual, Remediation Database, 2015.3.9.1, 2015.4.6.2,
Update, 09.04.2015 13:11:06, SYSTEM, JOHANNES-PC, Manual, Malware Database, 2015.3.9.5, 2015.4.9.4,
Protection, 09.04.2015 13:11:06, SYSTEM, JOHANNES-PC, Protection, Refresh, Starting,
Protection, 09.04.2015 13:11:06, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Stopping,
Protection, 09.04.2015 13:11:06, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Stopped,
Protection, 09.04.2015 13:11:11, SYSTEM, JOHANNES-PC, Protection, Refresh, Success,
Protection, 09.04.2015 13:11:11, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Starting,
Protection, 09.04.2015 13:11:11, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Started,
Detection, 09.04.2015 14:48:26, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.DataMgr.A, C:\Users\Johannes\AppData\Roaming\DataMgr\DataMgr.exe, Quarantäne, [2d5b77f3d9b1f83e843d6959e2213fc1]
Detection, 09.04.2015 14:48:30, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.DataMgr.A, c:\users\johannes\appdata\roaming\datamgr\datamgr.exe, Quarantine Failed, 2, Das System kann die angegebene Datei nicht finden. , [2d5b77f3d9b1f83e843d6959e2213fc1]
Detection, 09.04.2015 14:48:41, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.DataMgr.A, c:\users\johannes\appdata\roaming\datamgr\datamgr.exe, Quarantine Failed, 2, Das System kann die angegebene Datei nicht finden. , [2d5b77f3d9b1f83e843d6959e2213fc1]
Detection, 09.04.2015 14:48:49, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.DataMgr.A, c:\users\johannes\appdata\roaming\datamgr\datamgr.exe, Quarantine Failed, 2, Das System kann die angegebene Datei nicht finden. , [2d5b77f3d9b1f83e843d6959e2213fc1]
Protection, 09.04.2015 14:50:59, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Starting,
Protection, 09.04.2015 14:50:59, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Started,
Protection, 09.04.2015 14:50:59, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Starting,
Protection, 09.04.2015 14:52:12, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Started,
Detection, 09.04.2015 14:58:32, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, IP, 62.219.81.123, static.app.widdit.com, 49534, Outbound, C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe,
Detection, 09.04.2015 14:58:32, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, IP, 62.219.81.123, static.app.widdit.com, 49534, Outbound, C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe,
Detection, 09.04.2015 14:58:32, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, IP, 62.219.81.123, static.app.widdit.com, 49535, Outbound, C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe,
Update, 09.04.2015 15:24:39, SYSTEM, JOHANNES-PC, Scheduler, Malware Database, 2015.4.9.4, 2015.4.9.5,
Protection, 09.04.2015 15:24:39, SYSTEM, JOHANNES-PC, Protection, Refresh, Starting,
Protection, 09.04.2015 15:24:39, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Stopping,
Protection, 09.04.2015 15:24:40, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Stopped,
Protection, 09.04.2015 15:29:10, SYSTEM, JOHANNES-PC, Protection, Refresh, Success,
Protection, 09.04.2015 15:29:10, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Starting,
Protection, 09.04.2015 15:29:10, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Started,
Detection, 09.04.2015 16:49:35, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.BestToolBars.A, C:\Program Files (x86)\SeeSimilar\ScriptHost.dll, Quarantäne, [bbce2b3f6921f83e4f12d455e41ef30d]
Detection, 09.04.2015 16:49:38, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.SeeSimilar.A, C:\Program Files (x86)\SeeSimilar\BackgroundHost.exe, Quarantäne, [85041456aedcd066e18f664fb1528c74]
Detection, 09.04.2015 16:49:45, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.PiccShare.A, C:\Users\Johannes\AppData\Local\ext_piccshare\ext_piccshare.dll, Quarantäne, [83063f2bb4d6ac8a74a7900deb18f010]
Detection, 09.04.2015 16:49:52, SYSTEM, JOHANNES-PC, Protection, Malwareschutz, Datei, PUP.Optional.SeeSimilar.A, c:\program files (x86)\seesimilar\backgroundhost.exe, Quarantine Failed, 2, Das System kann die angegebene Datei nicht finden. , [85041456aedcd066e18f664fb1528c74]
Protection, 09.04.2015 16:54:13, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Starting,
Protection, 09.04.2015 16:54:14, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Started,
Protection, 09.04.2015 16:54:14, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Starting,
Protection, 09.04.2015 16:55:29, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Started,
Detection, 09.04.2015 17:06:13, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, IP, 62.219.81.123, static.app.widdit.com, 49251, Outbound, C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe,
Detection, 09.04.2015 17:06:13, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, IP, 62.219.81.123, static.app.widdit.com, 49251, Outbound, C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe,
Detection, 09.04.2015 17:06:13, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, IP, 62.219.81.123, static.app.widdit.com, 49254, Outbound, C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe,
Protection, 09.04.2015 17:18:30, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Starting,
Protection, 09.04.2015 17:18:30, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Started,
Protection, 09.04.2015 17:18:30, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Starting,
Protection, 09.04.2015 17:20:16, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Started,
Protection, 09.04.2015 18:11:10, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Starting,
Protection, 09.04.2015 18:11:10, SYSTEM, JOHANNES-PC, Protection, Malware Protection, Started,
Protection, 09.04.2015 18:11:10, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Starting,
Protection, 09.04.2015 18:11:10, SYSTEM, JOHANNES-PC, Protection, Malicious Website Protection, Started,
(end) Code:
# AdwCleaner v4.201 - Bericht erstellt 09/04/2015 um 18:13:29
# Aktualisiert 08/04/2015 von Xplode
# Datenbank : 2015-04-08.1 [Server]
# Betriebssystem : Windows 8.1 (x64)
# Benutzername : Johannes - JOHANNES-PC
# Gestarted von : C:\Users\Johannes\Downloads\AdwCleaner_4.201.exe
# Option : Suchlauf
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Geplante Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Internetbrowser ] *****
-\\ Internet Explorer v11.0.9600.17416
-\\ Mozilla Firefox v36.0.4 (x86 de)
*************************
AdwCleaner[R0].txt - [52560 Bytes] - [09/04/2015 17:09:54]
AdwCleaner[R1].txt - [702 Bytes] - [09/04/2015 18:13:29]
AdwCleaner[S0].txt - [50237 Bytes] - [09/04/2015 17:16:29]
########## EOF - C:\AdwCleaner\AdwCleaner[R1].txt - [820 Bytes] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.5.3 (04.07.2015:1)
OS: Windows 8.1 x64
Ran by Johannes on 09.04.2015 at 17:22:40,65
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
Successfully deleted: [File] "C:\WINDOWS\wininit.ini"
~~~ Folders
Successfully deleted: [Folder] "C:\ProgramData\flexnet"
~~~ FireFox
Successfully deleted: [File] C:\Users\Johannes\AppData\Roaming\mozilla\firefox\profiles\udgs4pa7.default\extensions\ff_v0.6@piccshare.com.xpi
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 09.04.2015 at 17:28:13,73
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-03-2015
Ran by Johannes (administrator) on JOHANNES-PC on 09-04-2015 18:16:52
Running from C:\Users\Johannes\Downloads
Loaded Profiles: Johannes (Available profiles: UpdatusUser & Johannes & Gast)
Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avcenter.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Dritek System INC.) C:\Windows\RfBtnSvc64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe
() C:\Windows\SysWOW64\srvany.exe
() C:\Windows\KMService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(The Chromium Authors) C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe
(The Chromium Authors) C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe
(The Chromium Authors) C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe
(The Chromium Authors) C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe
(The Chromium Authors) C:\Users\Johannes\AppData\Local\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Users\Johannes\Downloads\AdwCleaner_4.201.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [650648 2012-07-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12937872 2012-07-27] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1214608 2012-07-10] (Realtek Semiconductor)
HKLM\...\Run: [BtPreLoad] => C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [64640 2012-07-31] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [BakupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [533568 2012-08-22] (NTI Corporation)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Dolby PCEE4\pcee4.exe [508656 2012-07-25] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2995904 2012-07-11] (Symantec Corporation)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-03-18] (ArcSoft Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [726320 2015-04-07] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [129272 2015-03-16] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\...\Run: [EA Core] => "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [22869088 2014-10-21] (Google)
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\...\Run: [Google Update] => "C:\Users\Johannes\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\...\Run: [MusicManager] => C:\Users\Johannes\AppData\Local\Programs\Google\MusicManager\MusicManager.exe [7475200 2014-11-13] (Google Inc.)
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\...\Run: [Spotify Web Helper] => C:\Users\Johannes\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1964088 2015-04-08] (Spotify Ltd)
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\...\MountPoints2: {90d4c22a-4f94-11e3-bfe1-20689d450095} - "E:\SISetup.exe"
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\DREAMA~1.SCR
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Backup Manager Tray.lnk
ShortcutTarget: Acer Backup Manager Tray.lnk -> C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GoPro Importer.lnk
ShortcutTarget: GoPro Importer.lnk -> C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe (GoPro)
Startup: C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Johannes\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Johannes\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb6kMKStDbKgksVlAyRcvLHH_WOoCTYHw59xm38pQTg7DcGc4CrbQjzm4bd73xzWC221hEXM3h432EbOVjSYL8wo5kYPbuighSMtZydsJ9IPqC8tdV9Xvg8cpgK5UIGUwB8OqttP_AiZBxgeV3t5Yzg7Xlh3nMiqg,,
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb6kMKStDbKgksVlAyRcvLHH_WOoCTYHw59xm38pQTg7DcGc4CrbQjzm4bd73xzWC265fXWnUPtc9mxvgkqwfEc3yPsiEfUoqOP8UMBVsBXP7yN14Nu_3fUNA6FpUyP2YqH7uz0PGeOeiOGv6djnmqsaRmqGHA_Aw,,&q={searchTerms}
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRbkHo3StMBGUhCtXlT7G1muS_BRDXuH_N6QVFdlkuDDcdAb6kMKStDbKgksVlAyRcvLHH_WOoCTYHw59xm38pQTg7DcGc4CrbQjzm4bd73xzWC265fXWnUPtc9mxvgkqwfEc3yPsiEfUoqOP8UMBVsBXP7yN14Nu_3fUNA6FpUyP2YqH7uz0PGeOeiOGv6djnmqsaRmqGHA_Aw,,&q={searchTerms}
HKU\S-1-5-21-89369655-3679999935-2157184473-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-89369655-3679999935-2157184473-1002 -> {7716859D-5137-4A19-93F9-101D9A9FD28B} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2012-07-31] (Qualcomm Atheros Commnucations)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\udgs4pa7.default
FF SelectedSearchEngine: Search
FF DefaultSearchEngine: Search
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-05] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-05] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll No File
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-14] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [2013-05-04] ()
FF Plugin HKU\S-1-5-21-89369655-3679999935-2157184473-1002: @tools.google.com/Google Update;version=3 -> C:\Users\Johannes\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF Plugin HKU\S-1-5-21-89369655-3679999935-2157184473-1002: @tools.google.com/Google Update;version=9 -> C:\Users\Johannes\AppData\Local\Google\Update\1.3.25.11\npGoogleUpdate3.dll No File
FF SearchPlugin: C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\udgs4pa7.default\searchplugins\search_the_web.xml [2013-08-30]
FF Extension: FavGenius - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\udgs4pa7.default\Extensions\fg@favgenius.com.xpi [2015-03-30]
FF Extension: Simple New Tab - C:\Users\Johannes\AppData\Roaming\Mozilla\Firefox\Profiles\udgs4pa7.default\Extensions\snt@simplenewtab.com.xpi [2014-12-24]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
Chrome:
=======
CHR HKU\S-1-5-21-89369655-3679999935-2157184473-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Johannes\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [Not Found]
CHR HKU\S-1-5-21-89369655-3679999935-2157184473-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [docfnddcclkgokdfpnmngpiliiachclb] - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\ext_piccshare\ext_piccshare.crx [Not Found]
CHR HKU\S-1-5-21-89369655-3679999935-2157184473-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gbmdkmlcnbapgegninelmjbfibaghdmk] - C:\Users\Johannes\AppData\Local\Google\Chrome\User Data\Default\ext_offermosquito\ext_offermosquito.crx [Not Found]
CHR HKU\S-1-5-21-89369655-3679999935-2157184473-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - https://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-89369655-3679999935-2157184473-1002\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx [Not Found]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pggagllhehfjjfgnfnfkjedjlmbchamf] - C:\Users\Johannes\AppData\Roaming\SeeSimilar\SeeSimilar.crx [Not Found]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S2 AntiVirMailService; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [815920 2015-04-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [434424 2015-04-07] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [434424 2015-04-07] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [1004280 2015-04-07] (Avira Operations GmbH & Co. KG)
S2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [207488 2012-07-31] (Qualcomm Atheros Commnucations) [File not signed]
R2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [201008 2015-03-16] (Avira Operations GmbH & Co. KG)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
S2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2435728 2012-08-23] (Acer Incorporated)
S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [468624 2012-08-22] (Acer Incorporated)
S3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [658576 2012-08-22] (Acer Incorporated)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 KMService; C:\WINDOWS\SysWOW64\srvany.exe [8192 2014-03-31] () [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-03-17] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [3939008 2012-07-11] (Symantec Corporation)
S2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [259136 2012-08-22] (NTI Corporation)
R2 RfButtonDriverService; C:\Windows\RfBtnSvc64.exe [93296 2012-09-12] (Dritek System INC.)
S2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390672 2012-08-08] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
S2 ZAtheros Wlan Agent; C:\Program Files (x86)\Qualcomm Atheros\Ath_WlanAgent.exe [81536 2012-08-01] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [128536 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132120 2015-03-10] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-03-10] (Avira Operations GmbH & Co. KG)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-07-31] (Qualcomm Atheros)
R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R1 ccSet_NARA; C:\Windows\system32\drivers\NARAx64\0401000.00A\ccSetx64.sys [168608 2012-05-26] (Symantec Corporation)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-03-17] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-03-17] (Malwarebytes Corporation)
S3 mvusbews; C:\Windows\System32\Drivers\mvusbews.sys [20480 2012-12-24] (Marvell Semiconductor, Inc.)
R3 Ps2Kb2Hid; C:\Windows\System32\drivers\aPs2Kb2Hid.sys [26736 2012-09-12] (Dritek System Inc.)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [381440 2013-10-22] (Duplex Secure Ltd.)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
U3 DfSdkS; No ImagePath
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-09 17:28 - 2015-04-09 17:28 - 00000897 _____ () C:\Users\Johannes\Desktop\JRT.txt
2015-04-09 17:22 - 2015-04-09 17:22 - 02686959 _____ (Thisisu) C:\Users\Johannes\Downloads\JRT.exe
2015-04-09 17:22 - 2015-04-09 17:22 - 00000207 _____ () C:\WINDOWS\tweaking.com-regbackup-JOHANNES-PC-Windows-8.1-(64-bit).dat
2015-04-09 17:22 - 2015-04-09 17:22 - 00000000 ____D () C:\RegBackup
2015-04-09 17:09 - 2015-04-09 18:14 - 00000000 ____D () C:\AdwCleaner
2015-04-09 17:09 - 2015-04-09 17:09 - 02217984 _____ () C:\Users\Johannes\Downloads\AdwCleaner_4.201.exe
2015-04-09 17:08 - 2015-04-09 17:08 - 00006211 _____ () C:\mbam.txt
2015-04-09 17:07 - 2015-04-09 17:07 - 00006211 _____ () C:\Malware.txt
2015-04-09 16:53 - 2015-04-09 16:53 - 00292408 _____ () C:\WINDOWS\Minidump\040915-29296-01.dmp
2015-04-09 14:50 - 2015-04-09 14:50 - 00293176 _____ () C:\WINDOWS\Minidump\040915-31546-01.dmp
2015-04-09 13:10 - 2015-04-09 18:15 - 00136408 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-09 13:09 - 2015-04-09 13:09 - 00001118 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-04-09 13:09 - 2015-04-09 13:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-09 13:09 - 2015-04-09 13:09 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-04-09 13:09 - 2015-04-09 13:09 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-04-09 13:09 - 2015-03-17 06:15 - 00107736 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-09 13:09 - 2015-03-17 06:15 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-04-09 13:09 - 2015-03-17 06:15 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-04-09 13:06 - 2015-04-09 13:08 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Johannes\Downloads\mbam-setup-2.1.4.1018.exe
2015-04-08 12:08 - 2015-04-08 12:08 - 00001873 _____ () C:\Users\Johannes\Desktop\Spotify.lnk
2015-04-08 12:08 - 2015-04-08 12:08 - 00001859 _____ () C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-04-08 11:51 - 2015-04-08 11:51 - 05617096 _____ (Swearware) C:\Users\Johannes\Downloads\ComboFix (3).exe
2015-04-08 11:29 - 2015-04-08 11:30 - 00292408 _____ () C:\WINDOWS\Minidump\040815-31359-01.dmp
2015-04-08 11:27 - 2015-04-08 11:27 - 05617096 _____ (Swearware) C:\Users\Johannes\Downloads\ComboFix (2).exe
2015-04-08 11:26 - 2015-04-08 11:27 - 05617096 _____ (Swearware) C:\Users\Johannes\Downloads\ComboFix (1).exe
2015-04-08 11:25 - 2015-04-08 11:26 - 05617096 _____ (Swearware) C:\Users\Johannes\Downloads\ComboFix.exe
2015-04-08 11:12 - 2015-04-08 11:12 - 00001284 _____ () C:\Users\Johannes\Desktop\Revo Uninstaller.lnk
2015-04-08 11:12 - 2015-04-08 11:12 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2015-04-08 11:11 - 2015-04-08 11:11 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Johannes\Downloads\revosetup95.exe
2015-04-07 23:53 - 2015-04-07 23:53 - 00292696 _____ () C:\WINDOWS\Minidump\040715-29765-01.dmp
2015-04-07 16:30 - 2015-04-07 16:30 - 00047508 _____ () C:\Users\Johannes\Downloads\Addition.txt
2015-04-07 16:28 - 2015-04-09 18:16 - 00022240 _____ () C:\Users\Johannes\Downloads\FRST.txt
2015-04-07 16:28 - 2015-04-09 18:16 - 00000000 ____D () C:\FRST
2015-04-07 16:26 - 2015-04-07 16:26 - 02095616 _____ (Farbar) C:\Users\Johannes\Downloads\FRST64.exe
2015-04-07 15:00 - 2015-04-07 15:01 - 00293560 _____ () C:\WINDOWS\Minidump\040715-51875-01.dmp
2015-03-31 23:08 - 2015-03-31 23:09 - 00292792 _____ () C:\WINDOWS\Minidump\033115-24984-01.dmp
2015-03-31 22:42 - 2015-03-31 22:43 - 00293656 _____ () C:\WINDOWS\Minidump\033115-26984-01.dmp
2015-03-31 22:03 - 2015-03-31 22:03 - 00292792 _____ () C:\WINDOWS\Minidump\033115-26515-01.dmp
2015-03-31 20:21 - 2015-03-31 20:22 - 00292696 _____ () C:\WINDOWS\Minidump\033115-151375-01.dmp
2015-03-31 20:17 - 2015-03-31 20:17 - 00000000 __SHD () C:\found.000
2015-03-31 13:29 - 2015-03-31 13:30 - 00295576 _____ () C:\WINDOWS\Minidump\033115-24859-01.dmp
2015-03-31 12:31 - 2015-03-31 13:27 - 00023964 _____ () C:\Users\Johannes\Documents\untitled_AutoSave.gcs
2015-03-29 22:47 - 2015-03-29 22:47 - 00001175 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-03-29 22:47 - 2015-03-29 22:47 - 00001163 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-03-29 22:47 - 2015-03-29 22:47 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-03-29 22:44 - 2015-03-29 22:44 - 00243648 _____ () C:\Users\Johannes\Downloads\Firefox Setup Stub 36.0.4.exe
2015-03-25 16:36 - 2015-03-11 04:38 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-03-25 16:36 - 2015-03-11 00:08 - 01107456 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-03-25 16:36 - 2015-03-11 00:08 - 00943104 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-03-25 16:36 - 2015-03-11 00:08 - 00760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-03-25 16:36 - 2015-03-11 00:08 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-03-25 16:36 - 2015-03-11 00:08 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-03-25 16:36 - 2015-03-11 00:08 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-03-24 01:05 - 2015-03-24 01:05 - 00735304 _____ () C:\WINDOWS\Minidump\032415-19578-01.dmp
2015-03-22 12:23 - 2015-03-22 14:33 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\GoPro
2015-03-22 12:22 - 2015-03-22 18:48 - 00000000 ____D () C:\Users\Public\CineForm
2015-03-22 12:22 - 2015-03-22 12:22 - 00001128 _____ () C:\Users\Johannes\Desktop\GoPro Studio.lnk
2015-03-22 12:22 - 2015-03-22 12:22 - 00000000 ____D () C:\Users\Johannes\AppData\Local\GoPro
2015-03-22 12:22 - 2015-03-22 12:22 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GoPro
2015-03-22 12:22 - 2015-03-22 12:22 - 00000000 ____D () C:\Program Files (x86)\CineForm
2015-03-22 12:17 - 2015-03-22 12:22 - 00002272 _____ () C:\WINDOWS\DPINST.LOG
2015-03-22 12:17 - 2015-03-22 12:22 - 00000000 ____D () C:\Program Files (x86)\GoPro
2015-03-22 11:59 - 2015-03-22 11:59 - 01203488 _____ () C:\Users\Johannes\Downloads\GoPro Studio - CHIP-Installer.exe
2015-03-17 21:29 - 2015-03-17 21:29 - 00001516 _____ () C:\Users\Public\Desktop\Free Video Flip and Rotate.lnk
2015-03-17 21:25 - 2015-03-17 21:25 - 01203488 _____ () C:\Users\Johannes\Downloads\Free Video Flip and Rotate - CHIP-Installer.exe
2015-03-12 18:04 - 2015-02-07 01:09 - 00396419 _____ () C:\WINDOWS\system32\ApnDatabase.xml
2015-03-12 18:04 - 2015-02-04 01:58 - 00264000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-03-12 18:04 - 2015-02-04 01:58 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-03-12 18:04 - 2015-02-04 01:58 - 00044024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-03-12 18:04 - 2015-02-03 01:53 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2015-03-12 18:04 - 2015-02-03 01:53 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2015-03-12 18:04 - 2015-01-27 05:44 - 00933888 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-03-12 18:04 - 2015-01-24 03:51 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-03-12 18:04 - 2015-01-23 09:17 - 00723072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2015-03-12 18:04 - 2015-01-23 07:02 - 00560392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2015-03-12 18:03 - 2015-02-08 01:57 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-03-12 18:03 - 2015-02-08 01:49 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-03-12 18:03 - 2015-02-06 03:28 - 02257408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-03-12 18:03 - 2015-02-06 03:08 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-03-12 18:03 - 2015-02-05 22:24 - 01113920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-03-12 18:03 - 2015-02-03 02:03 - 03551744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2015-03-12 18:03 - 2015-02-03 02:02 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2015-03-12 18:03 - 2015-01-31 01:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-03-12 18:03 - 2015-01-31 01:29 - 02484224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-03-12 18:03 - 2015-01-30 05:01 - 00097792 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidbth.sys
2015-03-12 18:03 - 2015-01-30 05:00 - 00167424 ____C (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
2015-03-12 18:03 - 2015-01-30 04:03 - 01488896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
2015-03-12 18:03 - 2015-01-30 04:03 - 01464832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
2015-03-12 18:03 - 2015-01-30 04:02 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2015-03-12 18:03 - 2015-01-30 03:44 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42u.dll
2015-03-12 18:03 - 2015-01-30 03:42 - 01204224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42.dll
2015-03-12 18:03 - 2015-01-30 03:40 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2015-03-12 18:03 - 2015-01-30 03:37 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2015-03-12 18:03 - 2015-01-30 03:29 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
2015-03-12 18:03 - 2015-01-30 03:24 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2015-03-12 18:03 - 2015-01-30 03:24 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2015-03-12 18:03 - 2015-01-30 03:16 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2015-03-12 18:03 - 2015-01-30 03:08 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2015-03-12 18:03 - 2015-01-30 03:06 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2015-03-12 18:03 - 2015-01-29 03:58 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
2015-03-12 18:03 - 2015-01-29 03:29 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\photowiz.dll
2015-03-12 18:03 - 2015-01-29 03:11 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-12 18:03 - 2015-01-29 03:04 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-03-12 18:03 - 2015-01-29 03:04 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2015-03-12 18:03 - 2015-01-29 03:00 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-03-12 18:03 - 2015-01-29 02:59 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-03-12 18:03 - 2015-01-29 02:55 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-03-12 18:03 - 2015-01-29 02:50 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-03-12 18:03 - 2015-01-29 02:49 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-03-12 18:03 - 2015-01-28 04:24 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageContextHandler.dll
2015-03-12 18:03 - 2015-01-28 03:47 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StorageContextHandler.dll
2015-03-12 18:03 - 2015-01-28 01:47 - 02501368 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-03-12 18:03 - 2015-01-28 01:41 - 02207488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-03-12 18:03 - 2014-12-11 07:36 - 00046456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentServer.exe
2015-03-12 17:34 - 2015-03-06 04:53 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-03-12 17:34 - 2015-03-06 04:33 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-03-12 17:34 - 2015-02-26 01:26 - 04178944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-03-12 17:34 - 2015-02-20 05:03 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-03-12 17:34 - 2015-02-20 04:58 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-03-12 17:34 - 2015-02-20 04:20 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-03-12 17:34 - 2015-02-20 04:15 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-03-12 17:34 - 2015-01-31 01:20 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2015-03-12 17:34 - 2015-01-28 17:41 - 07472960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-03-12 17:34 - 2015-01-28 17:41 - 01733440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-03-12 17:34 - 2015-01-28 17:41 - 01498360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-03-12 17:34 - 2015-01-27 06:22 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2015-03-12 17:34 - 2015-01-27 04:11 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2015-03-12 17:32 - 2015-02-21 03:16 - 25021440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-03-12 17:32 - 2015-02-21 02:41 - 12827648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-03-12 17:32 - 2015-02-21 02:27 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-03-12 17:32 - 2015-02-21 02:27 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-03-12 17:32 - 2015-02-21 02:25 - 19720192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-03-12 17:32 - 2015-02-21 01:58 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-03-12 17:32 - 2015-02-21 01:32 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-03-12 17:32 - 2015-02-20 04:49 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-03-12 17:32 - 2015-02-20 04:48 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-03-12 17:32 - 2015-02-20 04:47 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-03-12 17:32 - 2015-02-20 04:35 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-03-12 17:32 - 2015-02-20 04:34 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2015-03-12 17:32 - 2015-02-20 04:32 - 06035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-03-12 17:32 - 2015-02-20 04:09 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-03-12 17:32 - 2015-02-20 04:07 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-03-12 17:32 - 2015-02-20 04:06 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-03-12 17:32 - 2015-02-20 04:05 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-03-12 17:32 - 2015-02-20 04:03 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-03-12 17:32 - 2015-02-20 03:59 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-03-12 17:32 - 2015-02-20 03:56 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-03-12 17:32 - 2015-02-20 03:52 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-03-12 17:32 - 2015-02-20 03:49 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-03-12 17:32 - 2015-02-20 03:49 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-03-12 17:32 - 2015-02-20 03:46 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-03-12 17:32 - 2015-02-20 03:43 - 14398976 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-03-12 17:32 - 2015-02-20 03:30 - 04300288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-03-12 17:32 - 2015-02-20 03:30 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-03-12 17:32 - 2015-02-20 03:29 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-03-12 17:32 - 2015-02-20 03:28 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-03-12 17:32 - 2015-02-20 03:26 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-03-12 17:32 - 2015-02-20 03:24 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-03-12 17:32 - 2015-02-20 03:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-03-12 17:32 - 2015-02-20 03:16 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-03-12 17:32 - 2015-02-20 03:03 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-03-12 17:32 - 2015-02-20 03:01 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-03-12 17:32 - 2015-02-20 02:57 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-03-12 17:32 - 2015-02-20 02:55 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-03-12 17:31 - 2015-02-12 19:40 - 22291584 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-03-12 17:31 - 2015-02-12 19:34 - 19731824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-03-12 17:31 - 2015-01-29 20:45 - 01763352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-03-12 17:31 - 2015-01-29 20:34 - 01488040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-03-12 17:31 - 2015-01-28 03:31 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2015-03-12 17:31 - 2015-01-28 03:11 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2015-03-12 17:30 - 2015-01-21 07:54 - 01384712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-03-12 17:30 - 2015-01-21 07:15 - 01123848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-09 18:15 - 2014-07-26 17:59 - 00001156 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-89369655-3679999935-2157184473-1002UA.job
2015-04-09 18:12 - 2013-05-03 17:24 - 00001142 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-09 18:02 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-04-09 17:41 - 2013-10-22 15:47 - 01603946 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-09 17:34 - 2013-12-26 21:20 - 00000000 ___DO () C:\Users\Johannes\SkyDrive
2015-04-09 17:33 - 2013-05-03 17:11 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-89369655-3679999935-2157184473-1002
2015-04-09 17:22 - 2014-03-15 12:18 - 00000000 ___RD () C:\Users\Johannes\Dropbox
2015-04-09 17:22 - 2014-03-14 22:20 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Dropbox
2015-04-09 17:22 - 2013-05-14 21:57 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-04-09 17:21 - 2014-04-26 20:37 - 00000000 ___RD () C:\Users\Johannes\Google Drive
2015-04-09 17:20 - 2014-12-09 22:57 - 00001384 _____ () C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome.lnk
2015-04-09 17:20 - 2014-12-09 22:55 - 00001359 _____ () C:\Users\Johannes\Desktop\Chrome.lnk
2015-04-09 17:18 - 2013-10-08 12:35 - 00001138 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cec41217e0faff.job
2015-04-09 17:17 - 2013-12-11 23:05 - 00036909 _____ () C:\WINDOWS\setupact.log
2015-04-09 17:17 - 2013-08-22 16:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-09 17:16 - 2014-09-25 15:06 - 00001066 _____ () C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
2015-04-09 17:16 - 2013-07-28 16:44 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Common
2015-04-09 16:53 - 2013-10-27 13:32 - 00000000 ____D () C:\WINDOWS\Minidump
2015-04-09 16:53 - 2013-04-03 10:30 - 696524741 _____ () C:\WINDOWS\MEMORY.DMP
2015-04-09 14:54 - 2013-10-22 15:23 - 00000000 ____D () C:\Users\Johannes
2015-04-09 14:50 - 2013-12-26 19:26 - 00273964 _____ () C:\WINDOWS\PFRO.log
2015-04-09 13:08 - 2013-05-11 17:05 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Adobe
2015-04-09 13:07 - 2013-10-28 21:23 - 00003954 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{965EBEB5-AFC7-45A7-A256-B0D90091556D}
2015-04-09 13:03 - 2014-08-18 13:55 - 00000000 ____D () C:\ProgramData\Package Cache
2015-04-09 13:03 - 2013-06-09 21:04 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-04-09 13:02 - 2013-06-09 21:04 - 00000000 ____D () C:\Program Files (x86)\Avira
2015-04-08 13:34 - 2013-08-22 15:25 - 00786432 ___SH () C:\WINDOWS\system32\config\BBI
2015-04-08 12:21 - 2013-05-07 17:36 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Spotify
2015-04-08 12:08 - 2013-05-07 17:36 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Spotify
2015-04-08 11:50 - 2013-09-30 06:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-04-08 11:50 - 2013-09-30 05:56 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat
2015-04-08 11:50 - 2013-09-30 05:56 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat
2015-04-08 11:22 - 2013-12-09 18:51 - 00000000 ____D () C:\ProgramData\Ashampoo
2015-04-08 11:15 - 2014-07-26 17:59 - 00001104 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-89369655-3679999935-2157184473-1002Core.job
2015-04-08 11:05 - 2014-03-15 12:18 - 00001083 _____ () C:\Users\Johannes\Desktop\Dropbox.lnk
2015-04-08 11:05 - 2014-03-14 22:21 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-07 15:15 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2015-04-07 14:47 - 2012-07-26 09:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2015-04-07 14:46 - 2013-06-09 21:10 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\Avira
2015-04-07 14:45 - 2013-06-09 21:04 - 00000000 ____D () C:\ProgramData\Avira
2015-03-31 13:23 - 2012-08-02 13:37 - 00000000 ____D () C:\ProgramData\Temp
2015-03-29 22:47 - 2013-09-13 16:06 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-29 22:47 - 2013-05-14 20:57 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Mozilla
2015-03-29 16:08 - 2014-10-08 22:58 - 00015174 _____ () C:\Users\Johannes\Documents\Lohn Oktober.xlsx
2015-03-29 16:04 - 2014-10-08 22:38 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Deployment
2015-03-29 15:48 - 2013-05-10 16:45 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\vlc
2015-03-27 18:31 - 2013-08-22 16:51 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-03-27 18:25 - 2013-05-05 00:59 - 122905848 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-03-25 17:26 - 2014-12-10 20:26 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-03-25 17:26 - 2014-07-10 17:22 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-03-17 21:29 - 2015-02-06 16:56 - 00001261 _____ () C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2015-03-17 21:29 - 2015-02-06 16:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-03-17 21:29 - 2015-02-06 16:56 - 00000000 ____D () C:\Program Files (x86)\DVDVideoSoft
2015-03-17 21:29 - 2013-05-07 22:47 - 00000000 ____D () C:\Users\Johannes\AppData\Roaming\DVDVideoSoft
2015-03-16 21:58 - 2013-05-04 11:39 - 00000000 ____D () C:\Users\Johannes\AppData\Local\Apple Computer
2015-03-16 19:32 - 2013-12-26 19:13 - 00000000 ____D () C:\Users\Public\CyberLink
2015-03-15 17:46 - 2013-05-04 11:27 - 00000000 ____D () C:\Users\Johannes\Documents\CyberLink
2015-03-14 21:01 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-03-14 12:35 - 2013-08-22 16:44 - 05112832 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2015-03-14 02:57 - 2013-08-22 17:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2015-03-14 02:57 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-14 02:57 - 2013-08-22 17:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-03-14 02:57 - 2013-08-22 17:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-03-14 02:57 - 2013-08-22 17:36 - 00000000 ____D () C:\WINDOWS\WinStore
2015-03-14 02:57 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-03-14 02:57 - 2013-08-22 17:36 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2015-03-14 00:15 - 2013-05-11 16:53 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-03-14 00:14 - 2012-07-26 07:26 - 00000199 _____ () C:\WINDOWS\win.ini
2015-03-13 21:47 - 2013-05-10 16:44 - 00001086 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2015-03-13 21:47 - 2013-05-10 16:44 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-03-10 16:49 - 2013-06-09 21:04 - 00132120 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2015-03-10 16:49 - 2013-06-09 21:04 - 00128536 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2015-03-10 16:49 - 2013-06-09 21:04 - 00043576 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
==================== Files in the root of some directories =======
2013-10-07 22:19 - 2013-10-07 22:19 - 5082084 _____ (The Public) C:\Users\Johannes\AppData\Roaming\Avisynth.exe
2013-10-07 22:19 - 2013-10-07 22:20 - 5243208 _____ ( ) C:\Users\Johannes\AppData\Roaming\AvsP.exe
2013-10-07 22:19 - 2013-10-07 22:19 - 5514668 _____ (LIGHTNING UK!) C:\Users\Johannes\AppData\Roaming\Imgburn.exe
2013-10-07 22:19 - 2013-10-07 22:19 - 1357348 _____ () C:\Users\Johannes\AppData\Roaming\MatroskaSplitter.exe
2013-10-07 22:20 - 2013-10-07 22:20 - 7760687 _____ (Boraxsoft) C:\Users\Johannes\AppData\Roaming\SetupGFD.exe
2013-05-03 19:14 - 2013-05-03 19:14 - 0000268 ___RH () C:\Users\Johannes\AppData\Roaming\SystemConfiguration
2013-05-03 19:14 - 2013-05-03 19:14 - 0000268 ___RH () C:\Users\Johannes\AppData\Roaming\Tables
2013-05-03 19:14 - 2013-05-03 19:14 - 0000268 ___RH () C:\Users\Johannes\AppData\Roaming\Techno Kit
2013-10-07 22:19 - 2013-10-07 22:19 - 0117723 _____ () C:\Users\Johannes\AppData\Roaming\yuvcodecs-1.3.exe
2013-08-19 19:07 - 2015-03-04 17:52 - 0012800 _____ () C:\Users\Johannes\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-05-11 15:48 - 2014-05-14 20:00 - 0000080 _____ () C:\Users\Johannes\AppData\Local\X-Plane Installer.prf
2013-05-11 12:18 - 2014-05-14 20:03 - 0000073 _____ () C:\Users\Johannes\AppData\Local\X-Plane_drm.prf
2013-05-11 12:19 - 2014-04-26 18:50 - 0000245 _____ () C:\Users\Johannes\AppData\Local\x-plane_install_10.txt
2012-09-12 19:08 - 2012-09-12 19:08 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2013-12-30 13:37 - 2013-12-30 13:45 - 0000303 _____ () C:\ProgramData\hpzinstall.log
2013-05-03 19:14 - 2013-05-03 19:14 - 0000020 ____H () C:\ProgramData\PKP_DLes.DAT
2013-05-03 19:14 - 2014-11-19 23:43 - 0000020 ____H () C:\ProgramData\PKP_DLet.DAT
2013-05-03 19:14 - 2014-11-06 22:38 - 0000020 ____H () C:\ProgramData\PKP_DLev.DAT
2013-05-03 19:14 - 2013-05-03 19:14 - 0000268 ___RH () C:\ProgramData\Textures
2013-05-03 19:14 - 2013-05-03 19:14 - 0000268 ___RH () C:\ProgramData\Themes
2013-05-03 19:14 - 2013-05-03 19:14 - 0000268 ___RH () C:\ProgramData\Track Settings
Some content of TEMP:
====================
C:\Users\Gast\AppData\Local\Temp\avgnt.exe
C:\Users\Johannes\AppData\Local\Temp\22kaxvks.dll
C:\Users\Johannes\AppData\Local\Temp\2bfge5eo.dll
C:\Users\Johannes\AppData\Local\Temp\6gofsl67.dll
C:\Users\Johannes\AppData\Local\Temp\a3onmuml.dll
C:\Users\Johannes\AppData\Local\Temp\AutoRun.exe
C:\Users\Johannes\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Johannes\AppData\Local\Temp\avgnt.exe
C:\Users\Johannes\AppData\Local\Temp\b6zeu71a.dll
C:\Users\Johannes\AppData\Local\Temp\cxoyhhlj.dll
C:\Users\Johannes\AppData\Local\Temp\cz0_zyus.dll
C:\Users\Johannes\AppData\Local\Temp\dbwk4i1y.dll
C:\Users\Johannes\AppData\Local\Temp\dhckg-lj.dll
C:\Users\Johannes\AppData\Local\Temp\dlfkctko.dll
C:\Users\Johannes\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp4cilep.dll
C:\Users\Johannes\AppData\Local\Temp\DseShExt-x64.dll
C:\Users\Johannes\AppData\Local\Temp\DseShExt-x86.dll
C:\Users\Johannes\AppData\Local\Temp\e57co--u.dll
C:\Users\Johannes\AppData\Local\Temp\e91tohsu.dll
C:\Users\Johannes\AppData\Local\Temp\fe7qt9oi.dll
C:\Users\Johannes\AppData\Local\Temp\fo-l87go.dll
C:\Users\Johannes\AppData\Local\Temp\FreeYouTubeToMP3Converter.exe
C:\Users\Johannes\AppData\Local\Temp\fztctfuz.dll
C:\Users\Johannes\AppData\Local\Temp\gk0msjmv.dll
C:\Users\Johannes\AppData\Local\Temp\gwoudkdh.dll
C:\Users\Johannes\AppData\Local\Temp\g_vvqi0j.dll
C:\Users\Johannes\AppData\Local\Temp\h9q_apes.dll
C:\Users\Johannes\AppData\Local\Temp\htsiki1c.dll
C:\Users\Johannes\AppData\Local\Temp\idkdfqzq.dll
C:\Users\Johannes\AppData\Local\Temp\Installer_Windows.exe
C:\Users\Johannes\AppData\Local\Temp\jm7nk1bz.dll
C:\Users\Johannes\AppData\Local\Temp\jr1f5vlj.dll
C:\Users\Johannes\AppData\Local\Temp\k-w5yhk7.dll
C:\Users\Johannes\AppData\Local\Temp\kgq1a-ge.dll
C:\Users\Johannes\AppData\Local\Temp\kpobcyc7.dll
C:\Users\Johannes\AppData\Local\Temp\krs04jpi.dll
C:\Users\Johannes\AppData\Local\Temp\lecoefcw.dll
C:\Users\Johannes\AppData\Local\Temp\loccgs4w.dll
C:\Users\Johannes\AppData\Local\Temp\lvz5r6vx.dll
C:\Users\Johannes\AppData\Local\Temp\mtpwvnir.dll
C:\Users\Johannes\AppData\Local\Temp\mx2ynl_o.dll
C:\Users\Johannes\AppData\Local\Temp\ose00000.exe
C:\Users\Johannes\AppData\Local\Temp\ozqqte2m.dll
C:\Users\Johannes\AppData\Local\Temp\pfn5v1qm.dll
C:\Users\Johannes\AppData\Local\Temp\q8j_3zps.dll
C:\Users\Johannes\AppData\Local\Temp\qtav92jm.dll
C:\Users\Johannes\AppData\Local\Temp\Quarantine.exe
C:\Users\Johannes\AppData\Local\Temp\qyrpczjx.dll
C:\Users\Johannes\AppData\Local\Temp\r-uuzkg7.dll
C:\Users\Johannes\AppData\Local\Temp\raoykoow.dll
C:\Users\Johannes\AppData\Local\Temp\s3pd_b8t.dll
C:\Users\Johannes\AppData\Local\Temp\SDShelEx-win32.dll
C:\Users\Johannes\AppData\Local\Temp\SDShelEx-x64.dll
C:\Users\Johannes\AppData\Local\Temp\siinst.exe
C:\Users\Johannes\AppData\Local\Temp\siuninst.exe
C:\Users\Johannes\AppData\Local\Temp\snfww3eq.dll
C:\Users\Johannes\AppData\Local\Temp\sqlite3.dll
C:\Users\Johannes\AppData\Local\Temp\strings.dll
C:\Users\Johannes\AppData\Local\Temp\ticmwmrm.dll
C:\Users\Johannes\AppData\Local\Temp\tmd_34011138.exe
C:\Users\Johannes\AppData\Local\Temp\tmd_34013832.exe
C:\Users\Johannes\AppData\Local\Temp\tmd_34018253.exe
C:\Users\Johannes\AppData\Local\Temp\tv7rzvor.dll
C:\Users\Johannes\AppData\Local\Temp\ukvr85sv.dll
C:\Users\Johannes\AppData\Local\Temp\vlc-2.1.5-win32.exe
C:\Users\Johannes\AppData\Local\Temp\vt0o2ejm.dll
C:\Users\Johannes\AppData\Local\Temp\vzdoii2g.dll
C:\Users\Johannes\AppData\Local\Temp\wxblsjuf.dll
C:\Users\Johannes\AppData\Local\Temp\xqh_t9ns.dll
C:\Users\Johannes\AppData\Local\Temp\y2ejay9g.dll
C:\Users\Johannes\AppData\Local\Temp\yrrrillk.dll
C:\Users\Johannes\AppData\Local\Temp\z2qgjzwv.dll
C:\Users\Johannes\AppData\Local\Temp\_xaktzhe.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-09 17:35
==================== End Of Log ============================ --- --- ---
--- --- --- |