Danke für die schnelle Antwort:)
habe alle Schritte ausgeführt, hier nun die logs die du wolltest. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.05.2014
Suchlauf-Zeit: 15:39:22
Logdatei: mbam.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.16.08
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8
CPU: x64
Dateisystem: NTFS
Benutzer: Sonja
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 307011
Verstrichene Zeit: 19 Min, 0 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 2
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\updateResultsAlpha.exe, 2124, Löschen bei Neustart, [ef29e36fe398e0569c12242ee71a39c7]
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\utilResultsAlpha.exe, 2208, Löschen bei Neustart, [2aee3a18e6957eb8e2cc0b47847dc838]
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 23
PUP.Optional.ResultsAlpha.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Update ResultsAlpha, In Quarantäne, [ef29e36fe398e0569c12242ee71a39c7],
PUP.Optional.ResultsAlpha.A, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Util ResultsAlpha, In Quarantäne, [2aee3a18e6957eb8e2cc0b47847dc838],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [f52363efe99252e44f765ffe41c120e0],
PUP.Optional.BrowseFox.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}, In Quarantäne, [f52363efe99252e44f765ffe41c120e0],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{cbab673a-a480-4050-bd2b-5de24a7a0282}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{F631E34D-23D3-4ED2-8942-631B8AAF9EA4}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{B01A1DA4-813F-44BD-B544-77E5DA7EB5A8}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{B01A1DA4-813F-44BD-B544-77E5DA7EB5A8}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{F631E34D-23D3-4ED2-8942-631B8AAF9EA4}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{CBAB673A-A480-4050-BD2B-5DE24A7A0282}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.ResultsAlpha.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{CBAB673A-A480-4050-BD2B-5DE24A7A0282}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.ResultsAlpha.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CBAB673A-A480-4050-BD2B-5DE24A7A0282}, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{828DC97A-2277-4E10-92A9-4907FA0922A9}, In Quarantäne, [68b0b89ae794290d411e342c11f114ec],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{828DC97A-2277-4E10-92A9-4907FA0922A9}, In Quarantäne, [68b0b89ae794290d411e342c11f114ec],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}, In Quarantäne, [ea2e074b18638babd688d9873dc5c23e],
PUP.Optional.BuenoSearch.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{F1C81E40-2485-4DB6-8C9D-04BD596B281E}, In Quarantäne, [ea2e074b18638babd688d9873dc5c23e],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ResultsAlpha, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, HKLM\SOFTWARE\WOW6432NODE\ResultsAlpha, In Quarantäne, [a7718ac8d0ab95a16d51fec2c53e45bb],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\acfoobbgoakpihljnfedbcfaipcdlfhk, In Quarantäne, [c454a2b00576c571ed142c8f5fa44bb5],
PUP.Optional.BuenoSearch.A, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Bueno Chrome Toolbar, In Quarantäne, [d048361c4f2c44f238bbe49d0ef4d32d],
PUP.Optional.ResultsAlpha.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\ResultsAlpha, In Quarantäne, [5eba480ae7941a1c03bc7848df24ac54],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE\1I1T1Q1S, In Quarantäne, [c454a5ad3c3fa98d6a20504bb151936d],
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE, In Quarantäne, [f6221b37047785b14c4e09a88a79d52b],
Registrierungswerte: 1
PUP.Optional.InstallCore.A, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\INSTALLCORE|tb, 0X2O1C0R2R1R, In Quarantäne, [f6221b37047785b14c4e09a88a79d52b]
Registrierungsdaten: 1
Hijack.StartPage, HKU\S-1-5-21-3822750039-1062396405-2383090701-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174, Gut: (hxxp://www.google.com), Schlecht: (hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174),Ersetzt,[ee2a89c9ccaf9f97b4c9d278d92b40c0]
Ordner: 4
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha, Löschen bei Neustart, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin, Löschen bei Neustart, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.BundleInstaller.A, C:\Users\Sonja\AppData\Roaming\1H1Q\Aff Packages, In Quarantäne, [0f0989c949326ec8a65d7cf7fc068878],
Dateien: 86
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\updateResultsAlpha.exe, Löschen bei Neustart, [ef29e36fe398e0569c12242ee71a39c7],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\utilResultsAlpha.exe, Löschen bei Neustart, [2aee3a18e6957eb8e2cc0b47847dc838],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\ResultsAlphaBHO.dll, In Quarantäne, [23f54210abd0bc7aa29ad159d42ecf31],
PUP.Optional.MultiPlug.A, C:\ProgramData\SaveClicker\ZXI1BWbYXJs.exe, In Quarantäne, [1afefa58b5c65adc73436ddcb74acb35],
PUP.Optional.InstallCore.A, C:\Users\Sonja\AppData\Local\Temp\ICReinstall_nssF58A.tmp, In Quarantäne, [1cfcbd954e2d79bde9c720042dd703fd],
PUP.Optional.InstallCore.A, C:\Users\Sonja\AppData\Local\Temp\ICReinstall_nsxBA2C.tmp, In Quarantäne, [5cbcc191304bd264c9e7889cb252857b],
PUP.Optional.YourFileDownloader, C:\Users\Sonja\AppData\Local\Temp\install559389062.exe, In Quarantäne, [0a0e470b80fb0d29de2cfc2216eae61a],
PUP.Optional.Amonetize, C:\Users\Sonja\AppData\Local\Temp\toolbar559329656.exe, In Quarantäne, [33e5b59d413a3600a035270dfd03f30d],
PUP.Optional.ToolBarInstaller.A, C:\Users\Sonja\AppData\Local\Temp\toolbar559649656.exe, In Quarantäne, [a771aba7b1ca5cdae78ae935887cf907],
PUP.Optional.BuenoSearch.A, C:\Users\Sonja\AppData\Local\Temp\~nsu.tmp\Au_.exe, In Quarantäne, [d8402c261b6093a3863fde9835ccff01],
PUP.Optional.YourFileDownloader, C:\Users\Sonja\Downloads\Die-Völker-1_downloader.exe, In Quarantäne, [011740120279d75f927818068a7605fb],
PUP.Optional.BundleInstaller.A, C:\Users\Sonja\Downloads\VideoConverterSetup(1).exe, In Quarantäne, [28f03f132952999d5d63938e689c4db3],
PUP.Optional.BundleInstaller.A, C:\Users\Sonja\Downloads\VideoConverterSetup.exe, In Quarantäne, [2deb9fb380fb8fa702beb1706e9652ae],
PUP.Optional.BuenoSearch.A, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\searchplugins\buenosearch.xml, In Quarantäne, [fa1ea5adee8d2d0974225d33e61c7d83],
PUP.Optional.ResultsAlpha.A, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\extensions\{f727685b-ed90-4adc-8eec-8234574a91e6}.xpi, In Quarantäne, [2deb0b475724072fce72d1c0748ebf41],
PUP.Optional.PCPerformer.A, C:\Windows\System32\roboot64.exe, In Quarantäne, [c850a8aa710acc6a2e41ccc9f60c01ff],
PUP.Optional.RegCleanerPro.J, C:\Windows\Tasks\RegClean Pro_UPDATES.job, In Quarantäne, [56c2da78097287af8e57f3aaef138779],
PUP.Optional.RegCleanPro.A, C:\Windows\Tasks\RegClean Pro_DEFAULT.job, In Quarantäne, [eb2d4e04bac1181e92a5b0000df65ca4],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\ResultsAlpha.ico, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\0, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\7za.exe, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\ResultsAlphaUninstall.exe, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\updateResultsAlpha.InstallState, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\ResultsAlpha.BrowserFilter.Helper.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\ResultsAlpha.BrowserFilter.Helper.dll.old.72937ef6-c7ce-47ef-bf01-40d307eadc13, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\ResultsAlpha.PurBrowse64.exe, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\ResultsAlpha.PurBrowseG.zip, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\ResultsAlphaBrowserFilter.exe, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\sqlite3.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\utilResultsAlpha.InstallState, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins\ResultsAlpha.Bromon.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins\ResultsAlpha.BrowserAdapterS.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins\ResultsAlpha.BrowserFilterG.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins\ResultsAlpha.CompatibilityChecker.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins\ResultsAlpha.FFUpdate.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins\ResultsAlpha.IEUpdate.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.ResultsAlpha.A, C:\Program Files (x86)\ResultsAlpha\bin\plugins\ResultsAlpha.PurBrowseG.dll, In Quarantäne, [021676dcc2b90e28427b47790201c63a],
PUP.Optional.BundleInstaller.A, C:\Users\Sonja\AppData\Roaming\1H1Q\Aff Packages\uninstaller.exe, In Quarantäne, [0f0989c949326ec8a65d7cf7fc068878],
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.admin", false);), Ersetzt,[8395a9a9c9b254e24db3e791877dc53b]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.aflt", "babsst");), Ersetzt,[c8503e1490eb70c619e760180202fd03]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");), Ersetzt,[ab6daaa82c4f1e18e11fbfb9a06418e8]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.autoRvrt", "false");), Ersetzt,[1cfc6ce680fb1521a45cfe7a768ede22]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.bbDpng", "16");), Ersetzt,[4eca450de79490a624dc60182fd5629e]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.cntry", "DE");), Ersetzt,[cf49ada51a61ea4cea16fd7b55afd42c]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.dfltLng", "en");), Ersetzt,[f72172e06417e353cd33cbad1aea4fb1]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.excTlbr", false);), Ersetzt,[a96fd979314ae2541be5c7b1d72df60a]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.ffxUnstlRst", true);), Ersetzt,[b4641e3487f4c86e9c645c1cfb092ed2]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.hdrMd5", "6BFBE4B517883C4FD56AB2DCADA36836");), Ersetzt,[1bfd0a482952cb6bfd030a6ec0446b95]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.id", "d46af3a20000000000008056f2a9c687");), Ersetzt,[b3650b47324972c4fe0274046a9a17e9]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.instlDay", "16131");), Ersetzt,[cb4d4e04c8b3053135cb215749bb3ac6]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.instlRef", "sst");), Ersetzt,[26f2e76ba4d7d75ffa064b2de81c7f81]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.lastB", "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");), Ersetzt,[0414e86a314ae1556d93eb8dda2a57a9]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.lastVrsnTs", "1.8.28.720:25:20");), Ersetzt,[5bbdcc86176477bfba461167bb49b34d]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.newTab", false);), Ersetzt,[e731450d4e2dfa3c18e85c1c2ed6e21e]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.prdct", "buenosearch");), Ersetzt,[42d6f260007bf343eb15e0985aaa7090]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.prtnrId", "buenosearch");), Ersetzt,[0e0a9db599e2e25402feb1c761a3d828]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.rvrt", "false");), Ersetzt,[50c84f031c5fc37344bc5f19df258c74]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.sg", "azb");), Ersetzt,[a5738dc598e374c214ecbabe838149b7]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.smplGrp", "none");), Ersetzt,[70a8470b0b70f34304fc403860a47b85]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");), Ersetzt,[ba5e351d02796fc74ab68bed10f4cc34]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tlbrId", "base");), Ersetzt,[7b9dc9897cff9c9a59a70d6bce369868]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");), Ersetzt,[c85075ddc3b8f145ab55572148bcce32]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7");), Ersetzt,[b2660a482d4ebc7ae7190e6ad33153ad]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.720:25:20");), Ersetzt,[28f05ef47407231323dd88f01aea57a9]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7");), Ersetzt,[a6724909b0cbf2444eb2e29653b18779]
PUP.Optional.BuenoSearch.A, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");), Ersetzt,[799f99b91a616dc9b849b3c4bf456c94]
PUP.Optional.BuenoSearch.A, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");), Ersetzt,[27f192c0413a3df9c140185fb351d22e]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.id", "d46af3a20000000000008056f2a9c687");), Ersetzt,[66b2272beb908fa7847b651220e4bb45]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");), Ersetzt,[04145af8b6c52e0803fce6919e663bc5]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.instlDay", "16131");), Ersetzt,[1206b0a2e7944fe76a9575020bf923dd]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.vrsn", "1.8.28.7");), Ersetzt,[0018252d93e8ce68a6594b2cb94b12ee]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.vrsni", "1.8.28.7");), Ersetzt,[1ff91d355e1dea4ca45b126557adcd33]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.vrsnTs", "1.8.28.720:25:20");), Ersetzt,[f226ed651665999d6f905027ac58ee12]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.prtnrId", "buenosearch");), Ersetzt,[37e1a6acbcbffc3a728d1e59fe0616ea]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.prdct", "buenosearch");), Ersetzt,[fe1a0052b0cbbd79dc23c0b75da72ad6]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.aflt", "babsst");), Ersetzt,[7a9e351da0dba88e9a653542c242857b]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.smplGrp", "none");), Ersetzt,[1107133f0576b87e22dd6a0d976def11]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.tlbrId", "base");), Ersetzt,[47d11a38017abe784db2fe79b74d728e]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.instlRef", "sst");), Ersetzt,[25f3e46eb1ca2d0952ad36411ce811ef]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.dfltLng", "en");), Ersetzt,[20f882d092e93afc659a4f2807fd4cb4]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.excTlbr", false);), Ersetzt,[5dbbf161c7b4fe38d02f473018ecb54b]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.ffxUnstlRst", true);), Ersetzt,[4bcd2b2799e2b581b04fd5a2ea1a24dc]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.admin", false);), Ersetzt,[a1779eb4e19a6bcbe916a6d18f75ea16]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.autoRvrt", "false");), Ersetzt,[50c821311c5ffc3a68972b4cc53f9e62]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.rvrt", "false");), Ersetzt,[e63284cefa8183b31ae53047c044748c]
PUP.Optional.BuenoSearch, C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js, Gut: (), Schlecht: (user_pref("extensions.buenosearch.newTab", false);), Ersetzt,[a1778ec47a01f93d6c93294e39cb8f71]
Physische Sektoren: 0
(No malicious items detected)
(end) Code:
# AdwCleaner v3.208 - Bericht erstellt am 16/05/2014 um 15:54:35
# Aktualisiert 11/05/2014 von Xplode
# Betriebssystem : Windows 8 (64 bits)
# Benutzername : Sonja - LAPTOP
# Gestartet von : C:\Users\Sonja\Desktop\adwcleaner_3.208.exe
# Option : Löschen
***** [ Dienste ] *****
[#] Dienst Gelöscht : SystemStoreService
[#] Dienst Gelöscht : VOsrv
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\ProgramData\Systweak
Ordner Gelöscht : C:\ProgramData\SaveClicker
Ordner Gelöscht : C:\Program Files (x86)\SearchProtect
Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater
Ordner Gelöscht : C:\Program Files (x86)\SaveClicker
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\torch
Ordner Gelöscht : C:\Users\Gast\AppData\Local\torch
Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\torch
Ordner Gelöscht : C:\Users\Sonja\AppData\Local\SoftwareUpdater
Ordner Gelöscht : C:\Users\Sonja\AppData\Local\torch
Ordner Gelöscht : C:\Users\Sonja\AppData\Roaming\1H1Q
Ordner Gelöscht : C:\Users\Sonja\AppData\Roaming\Systweak
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\torch
Ordner Gelöscht : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\Extensions\3g9.j@siek-okewg.net
Ordner Gelöscht : C:\Users\Sonja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\adlkedknnlogbhknnnaclbilhjpehhib
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\adlkedknnlogbhknnnaclbilhjpehhib
Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\adlkedknnlogbhknnnaclbilhjpehhib
Ordner Gelöscht : C:\Users\Sonja\AppData\Local\Google\Chrome\User Data\Default\Extensions\adlkedknnlogbhknnnaclbilhjpehhib
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\adlkedknnlogbhknnnaclbilhjpehhib
Ordner Gelöscht : C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dblbmminjbfkkjjgcclnhejdhkajjjon
Ordner Gelöscht : C:\Users\Gast\AppData\Local\Google\Chrome\User Data\Default\Extensions\dblbmminjbfkkjjgcclnhejdhkajjjon
Ordner Gelöscht : C:\Users\HomeGroupUser$\AppData\Local\Google\Chrome\User Data\Default\Extensions\dblbmminjbfkkjjgcclnhejdhkajjjon
Ordner Gelöscht : C:\Users\Sonja\AppData\Local\Google\Chrome\User Data\Default\Extensions\dblbmminjbfkkjjgcclnhejdhkajjjon
Ordner Gelöscht : C:\Users\UpdatusUser\AppData\Local\Google\Chrome\User Data\Default\Extensions\dblbmminjbfkkjjgcclnhejdhkajjjon
Datei Gelöscht : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\Extensions\{5ebdca98-43b3-45bb-87e0-716029fb42ab}.xpi
Datei Gelöscht : C:\END
Datei Gelöscht : C:\Users\Public\Desktop\eBay.lnk
Datei Gelöscht : C:\Users\Sonja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\lollipop.lnk
Datei Gelöscht : C:\Users\Sonja\Desktop\Continue VuuPC Installation.lnk
Datei Gelöscht : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\invalidprefs.js
Datei Gelöscht : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\user.js
Datei Gelöscht : C:\Windows\System32\Tasks\Advanced System Protector_startup
Datei Gelöscht : C:\Windows\System32\Tasks\EPUpdater
Datei Gelöscht : C:\Windows\Tasks\FoxTab.job
Datei Gelöscht : C:\Windows\System32\Tasks\FoxTab
Datei Gelöscht : C:\Windows\System32\Tasks\RegClean Pro
Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater Ui
Datei Gelöscht : C:\Windows\System32\Tasks\Software Updater
Datei Gelöscht : C:\Windows\System32\Tasks\YourFile DownloaderUpdate
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AdvancedSystemProtector_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Schlüssel Gelöscht : HKCU\Software\powerpack
Schlüssel Gelöscht : HKLM\Software\systweak
***** [ Browser ] *****
-\\ Internet Explorer v10.0.9200.16537
-\\ Mozilla Firefox v29.0.1 (de)
[ Datei : C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default\prefs.js ]
Zeile gelöscht : user_pref("extensions.YqRHwu7gcg6h.scode", "(function(){try{var url=(window.self.location.href + document.cookie);if(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sum[...]
Zeile gelöscht : user_pref("extensions.buenosearch.admin", false);
Zeile gelöscht : user_pref("extensions.buenosearch.aflt", "babsst");
Zeile gelöscht : user_pref("extensions.buenosearch.appId", "{37EB75F2-7392-4DBE-B5AD-147EC6D7BF5F}");
Zeile gelöscht : user_pref("extensions.buenosearch.autoRvrt", "false");
Zeile gelöscht : user_pref("extensions.buenosearch.bbDpng", "16");
Zeile gelöscht : user_pref("extensions.buenosearch.cntry", "DE");
Zeile gelöscht : user_pref("extensions.buenosearch.dfltLng", "en");
Zeile gelöscht : user_pref("extensions.buenosearch.excTlbr", false);
Zeile gelöscht : user_pref("extensions.buenosearch.ffxUnstlRst", true);
Zeile gelöscht : user_pref("extensions.buenosearch.hdrMd5", "6BFBE4B517883C4FD56AB2DCADA36836");
Zeile gelöscht : user_pref("extensions.buenosearch.id", "d46af3a20000000000008056f2a9c687");
Zeile gelöscht : user_pref("extensions.buenosearch.instlDay", "16131");
Zeile gelöscht : user_pref("extensions.buenosearch.instlRef", "sst");
Zeile gelöscht : user_pref("extensions.buenosearch.lastB", "hxxp://www.buenosearch.com/?babsrc=HP_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");
Zeile gelöscht : user_pref("extensions.buenosearch.lastVrsnTs", "1.8.28.720:25:20");
Zeile gelöscht : user_pref("extensions.buenosearch.newTab", false);
Zeile gelöscht : user_pref("extensions.buenosearch.prdct", "buenosearch");
Zeile gelöscht : user_pref("extensions.buenosearch.prtnrId", "buenosearch");
Zeile gelöscht : user_pref("extensions.buenosearch.rvrt", "false");
Zeile gelöscht : user_pref("extensions.buenosearch.sg", "azb");
Zeile gelöscht : user_pref("extensions.buenosearch.smplGrp", "none");
Zeile gelöscht : user_pref("extensions.buenosearch.tb_url", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");
Zeile gelöscht : user_pref("extensions.buenosearch.tlbrId", "base");
Zeile gelöscht : user_pref("extensions.buenosearch.tlbrSrchUrl", "hxxp://www.buenosearch.com/?q={searchTerms}&babsrc=TB_ss&mntrId=D46A8056F2A9C687&affID=128235&tsp=5174");
Zeile gelöscht : user_pref("extensions.buenosearch.vrsn", "1.8.28.7");
Zeile gelöscht : user_pref("extensions.buenosearch.vrsnTs", "1.8.28.720:25:20");
Zeile gelöscht : user_pref("extensions.buenosearch.vrsni", "1.8.28.7");
-\\ Google Chrome v
[ Datei : C:\Users\Sonja\AppData\Local\Google\Chrome\User Data\Default\preferences ]
*************************
AdwCleaner[R0].txt - [7324 octets] - [16/05/2014 15:53:36]
AdwCleaner[S0].txt - [7201 octets] - [16/05/2014 15:54:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7261 octets] ########## Code:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8 x64
Ran by Sonja on 16.05.2014 at 16:02:40,96
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{995F4BA9-CC4A-41A0-B361-FA996141DF9F}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{995F4BA9-CC4A-41A0-B361-FA996141DF9F}
~~~ Files
~~~ Folders
~~~ FireFox
Emptied folder: C:\Users\Sonja\AppData\Roaming\mozilla\firefox\profiles\rl350ko8.default\minidumps [4 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 16.05.2014 at 16:10:58,00
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-05-2014
Ran by Sonja (administrator) on LAPTOP on 16-05-2014 16:16:50
Running from C:\Users\Sonja\Desktop
Platform: Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccsvchst.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-28] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3053808 2013-04-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2013-05-22] (CyberLink Corp.)
HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-07-24] (Hewlett-Packard Company)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-12-25] (Hewlett-Packard Development Company, L.P.)
HKLM\...\RunOnce: [NCPluginUpdater] - "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update [21720 2014-04-22] (Hewlett-Packard)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3822750039-1062396405-2383090701-1002\...\Run: [lollipop_02181301] => "c:\users\sonja\appdata\local\lollipop\lollipop_02181301.exe" lollipop_02181301
HKU\S-1-5-21-3822750039-1062396405-2383090701-1002\...\Run: [Power2GoExpress8] => C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe [1713416 2013-08-05] (CyberLink Corp.)
HKU\S-1-5-21-3822750039-1062396405-2383090701-1002\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3666224 2013-09-20] (Safer-Networking Ltd.)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [245872 2013-05-25] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [201576 2013-05-25] (NVIDIA Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\phase6_18_erinnerung.lnk
ShortcutTarget: phase6_18_erinnerung.lnk -> C:\Program Files (x86)\phase6\phase6_18\WinStart\WinStart.exe (phase6)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPNOT13/4
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPNOT13/4
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=HPNTDFJS
SearchScopes: HKLM - {995F4BA9-CC4A-41A0-B361-FA996141DF9F} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&fr=vc_trans_8140&type=horus
SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.)
BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\IPS\IPSBHO.DLL (Symantec Corporation)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\coIEPlg.dll (Symantec Corporation)
Toolbar: HKCU - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Sonja\AppData\Roaming\Mozilla\Firefox\Profiles\rl350ko8.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Widget context - C:\Users\Sonja\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{140A2D0E-85CC-4ed3-9BA5-8FA35DA7FABA}.xpi [2014-02-18]
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\coFFPlgn\
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\coFFPlgn\ []
FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\IPSFF
FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\IPSFF [2014-01-11]
Chrome:
=======
CHR Extension: (No Name) - C:\Users\Sonja\AppData\Local\Google\Chrome\User Data\Default\Extensions\adlkedknnlogbhknnnaclbilhjpehhib [2014-02-13]
CHR Extension: (No Name) - C:\Users\Sonja\AppData\Local\Google\Chrome\User Data\Default\Extensions\dblbmminjbfkkjjgcclnhejdhkajjjon [2014-02-13]
CHR Extension: (No Name) - C:\Users\Sonja\AppData\Local\Google\Chrome\User Data\Default\Extensions\ombmmloebnfnpehgjnmkcgoegfachobp [2014-02-17]
CHR HKLM-x32\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\Exts\Chrome.crx [2014-05-05]
==================== Services (Whitelisted) =================
R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-09-05] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-09-05] (CyberLink)
R2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-12-25] (Hewlett-Packard Development Company, L.P.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-08] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-08] (Intel Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.)
R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.5.0.28\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [245832 2013-05-17] (Realtek Semiconductor)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [3921880 2013-10-15] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1042272 2013-09-20] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171416 2013-09-13] (Safer-Networking Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2014-03-29] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\BASHDefs\20140214.001\BHDrvx64.sys [1526488 2013-12-18] (Symantec Corporation)
R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1405000.01C\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484952 2014-01-10] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [137648 2014-01-10] (Symantec Corporation)
R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\IPSDefs\20140311.001\IDSvia64.sys [524504 2014-03-06] (Symantec Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99800 2013-05-08] (Intel Corporation)
S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140312.001\ENG64.SYS [126040 2014-01-10] (Symantec Corporation)
S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.3.0.36\Definitions\VirusDefs\20140312.001\EX64.SYS [2099288 2014-01-10] (Symantec Corporation)
U5 RTSPER; C:\Windows\System32\Drivers\RTSPER.sys [408136 2013-05-09] (Realsil Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2982104 2014-04-10] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29424 2013-04-24] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-04-24] (Synaptics Incorporated)
S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1405000.01C\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation)
R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1405000.01C\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation)
R3 SymDS; C:\Windows\system32\drivers\NISx64\1405000.01C\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation)
R3 SymEFA; C:\Windows\system32\drivers\NISx64\1405000.01C\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation)
S4 SymELAM; C:\Windows\system32\drivers\NISx64\1405000.01C\SymELAM.sys [23448 2012-11-15] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2014-01-11] (Symantec Corporation)
R3 SymIRON; C:\Windows\system32\drivers\NISx64\1405000.01C\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation)
R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1405000.01C\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
R1 {f727685b-ed90-4adc-8eec-8234574a91e6}Gw64; C:\Windows\System32\drivers\{f727685b-ed90-4adc-8eec-8234574a91e6}Gw64.sys [61120 2014-04-24] (StdLib)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-05-16 16:16 - 2014-05-16 16:16 - 00000000 ____D () C:\Users\Sonja\Desktop\FRST-OlderVersion
2014-05-16 16:10 - 2014-05-16 16:10 - 00001036 _____ () C:\Users\Sonja\Desktop\JRT.txt
2014-05-16 16:02 - 2014-05-16 16:02 - 00000000 ____D () C:\Windows\ERUNT
2014-05-16 16:00 - 2014-05-16 16:00 - 01016261 _____ (Thisisu) C:\Users\Sonja\Desktop\JRT.exe
2014-05-16 15:53 - 2014-05-16 15:54 - 00000000 ____D () C:\AdwCleaner
2014-05-16 15:53 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\SysWOW64\sqlite3.dll
2014-05-16 15:49 - 2014-05-16 15:50 - 01325827 _____ () C:\Users\Sonja\Desktop\adwcleaner_3.208.exe
2014-05-16 15:45 - 2014-05-16 15:45 - 00024037 _____ () C:\Users\Sonja\Desktop\mbam.txt
2014-05-16 15:18 - 2014-05-16 15:42 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 15:18 - 2014-05-16 15:18 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 15:18 - 2014-05-16 15:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 15:18 - 2014-05-16 15:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 15:18 - 2014-05-16 15:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 15:18 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-05-16 15:18 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-05-16 15:18 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-05-16 15:14 - 2014-05-16 15:17 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Sonja\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-16 14:54 - 2014-05-16 14:54 - 00001275 _____ () C:\Users\Sonja\Desktop\Revo Uninstaller.lnk
2014-05-16 14:54 - 2014-05-16 14:54 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-16 14:53 - 2014-05-16 14:54 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Sonja\Downloads\revosetup95.exe
2014-05-14 14:59 - 2014-05-14 14:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-05-14 13:30 - 2014-05-14 13:30 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Internet Security
2014-05-14 13:21 - 2014-05-14 13:22 - 00297224 _____ () C:\Windows\Minidump\051414-63125-01.dmp
2014-05-14 13:06 - 2014-05-14 13:06 - 00010574 _____ () C:\Users\Sonja\Desktop\Gmer.txt
2014-05-14 12:59 - 2014-05-14 12:59 - 00380416 _____ () C:\Users\Sonja\Desktop\Gmer-19357.exe
2014-05-14 12:54 - 2014-05-14 12:54 - 00036535 _____ () C:\Users\Sonja\Desktop\Addition.txt
2014-05-14 12:53 - 2014-05-16 16:16 - 00018844 _____ () C:\Users\Sonja\Desktop\FRST.txt
2014-05-14 12:53 - 2014-05-16 16:16 - 00000000 ____D () C:\FRST
2014-05-14 12:51 - 2014-05-16 16:16 - 02067456 _____ (Farbar) C:\Users\Sonja\Desktop\FRST64.exe
2014-05-14 12:48 - 2014-05-14 12:48 - 00000472 _____ () C:\Users\Sonja\Desktop\defogger_disable.log
2014-05-14 12:48 - 2014-05-14 12:48 - 00000000 _____ () C:\Users\Sonja\defogger_reenable
2014-05-14 12:46 - 2014-05-14 12:46 - 00050477 _____ () C:\Users\Sonja\Desktop\Defogger.exe
2014-05-14 12:34 - 2014-03-28 10:23 - 19759104 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-05-14 12:34 - 2014-03-28 08:18 - 17562112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-05-14 12:33 - 2014-04-12 11:27 - 00172888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-05-14 12:33 - 2014-04-12 11:10 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-05-14 12:33 - 2014-04-12 11:09 - 01043968 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-05-14 12:33 - 2014-04-12 11:09 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-05-14 12:33 - 2014-04-12 11:09 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-05-14 12:33 - 2014-04-12 11:09 - 00094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-05-14 12:33 - 2014-04-12 11:08 - 01281536 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-05-14 12:33 - 2014-04-12 11:08 - 00827904 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-05-14 12:33 - 2014-04-12 11:08 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll
2014-05-14 12:33 - 2014-04-12 11:08 - 00318464 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-05-14 12:33 - 2014-04-12 11:07 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-05-14 12:33 - 2014-04-12 09:23 - 00961536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2014-05-14 12:33 - 2014-04-12 09:23 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-05-14 12:33 - 2014-04-12 09:23 - 00273920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2014-05-14 12:33 - 2014-04-12 09:23 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2014-05-14 12:33 - 2014-04-12 09:23 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-05-14 12:33 - 2014-04-12 09:22 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2014-05-14 12:33 - 2014-04-12 09:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-05-14 12:33 - 2014-04-12 08:58 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\workerdd.dll
2014-05-14 12:33 - 2014-03-28 21:19 - 00035856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2014-05-14 12:33 - 2014-03-24 00:11 - 00269592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2014-05-14 12:33 - 2014-03-11 05:32 - 06987096 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-05-14 12:33 - 2014-03-11 05:25 - 00100184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-05-14 12:33 - 2014-03-11 02:41 - 00559104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll
2014-05-14 12:33 - 2014-03-11 02:41 - 00323072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2014-05-14 12:33 - 2014-03-11 02:41 - 00038400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll
2014-05-14 12:33 - 2014-03-11 02:39 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-05-14 12:33 - 2014-03-11 02:38 - 00982016 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-05-14 12:33 - 2014-03-11 02:38 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-05-14 12:33 - 2014-03-11 02:38 - 00419328 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-05-14 12:33 - 2014-03-11 02:38 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2014-05-14 12:33 - 2014-03-11 02:38 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-05-14 12:33 - 2014-03-11 02:38 - 00045056 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-05-14 12:33 - 2014-03-11 02:38 - 00027648 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-05-14 12:33 - 2014-03-10 05:05 - 00668160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2014-05-14 12:33 - 2014-03-10 03:27 - 00099840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2014-05-14 12:33 - 2014-03-04 01:07 - 00570216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-05-14 12:32 - 2014-05-06 07:14 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-14 12:32 - 2014-05-06 07:14 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-14 12:32 - 2014-05-06 05:48 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-14 12:32 - 2014-05-06 05:48 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-14 12:32 - 2014-05-06 05:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-14 12:32 - 2014-05-06 05:26 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-14 12:32 - 2014-03-28 10:23 - 01287168 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-05-14 12:28 - 2014-03-01 11:47 - 01258496 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-05-14 12:28 - 2014-03-01 11:47 - 01120768 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2014-05-14 12:28 - 2014-03-01 10:07 - 01075200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2014-05-14 12:28 - 2014-03-01 08:59 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-05-14 12:28 - 2014-02-27 01:18 - 00621568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-05-14 12:28 - 2014-02-27 01:18 - 00370688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-05-14 12:28 - 2014-02-27 01:18 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-05-14 12:28 - 2014-02-27 01:18 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-05-14 12:28 - 2014-02-15 06:15 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-05-12 13:07 - 2014-05-12 13:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-07 10:48 - 2014-04-19 11:39 - 00628024 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-05-07 10:48 - 2014-04-19 10:45 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-05-07 10:48 - 2014-04-19 10:45 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-07 10:48 - 2014-04-19 08:57 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-05-07 10:48 - 2014-04-19 08:57 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-05-05 15:28 - 2014-04-24 12:30 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\{f727685b-ed90-4adc-8eec-8234574a91e6}Gw64.sys
2014-04-28 11:41 - 2014-04-28 11:42 - 00000000 ____D () C:\Users\Sonja\Desktop\FH
2014-04-28 11:39 - 2014-04-28 11:43 - 00000000 ____D () C:\Users\Sonja\Desktop\Wohnung
==================== One Month Modified Files and Folders =======
2014-05-16 16:17 - 2014-05-14 12:53 - 00018844 _____ () C:\Users\Sonja\Desktop\FRST.txt
2014-05-16 16:16 - 2014-05-16 16:16 - 00000000 ____D () C:\Users\Sonja\Desktop\FRST-OlderVersion
2014-05-16 16:16 - 2014-05-14 12:53 - 00000000 ____D () C:\FRST
2014-05-16 16:16 - 2014-05-14 12:51 - 02067456 _____ (Farbar) C:\Users\Sonja\Desktop\FRST64.exe
2014-05-16 16:16 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\sru
2014-05-16 16:10 - 2014-05-16 16:10 - 00001036 _____ () C:\Users\Sonja\Desktop\JRT.txt
2014-05-16 16:02 - 2014-05-16 16:02 - 00000000 ____D () C:\Windows\ERUNT
2014-05-16 16:02 - 2013-07-22 19:32 - 00831158 _____ () C:\Windows\system32\perfh007.dat
2014-05-16 16:02 - 2013-07-22 19:32 - 00188760 _____ () C:\Windows\system32\perfc007.dat
2014-05-16 16:02 - 2012-07-26 09:28 - 01952918 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-05-16 16:00 - 2014-05-16 16:00 - 01016261 _____ (Thisisu) C:\Users\Sonja\Desktop\JRT.exe
2014-05-16 15:57 - 2014-01-11 21:25 - 00000000 ____D () C:\Users\Sonja\Documents\Youcam
2014-05-16 15:56 - 2014-01-22 21:51 - 00000000 ____D () C:\Users\Public\Documents\phase6_18_Daten
2014-05-16 15:55 - 2012-08-04 00:23 - 00141518 _____ () C:\Windows\PFRO.log
2014-05-16 15:55 - 2012-07-26 09:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-05-16 15:54 - 2014-05-16 15:53 - 00000000 ____D () C:\AdwCleaner
2014-05-16 15:50 - 2014-05-16 15:49 - 01325827 _____ () C:\Users\Sonja\Desktop\adwcleaner_3.208.exe
2014-05-16 15:45 - 2014-05-16 15:45 - 00024037 _____ () C:\Users\Sonja\Desktop\mbam.txt
2014-05-16 15:42 - 2014-05-16 15:18 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-05-16 15:40 - 2014-01-13 18:24 - 00000346 _____ () C:\Windows\Tasks\HPCeeScheduleForSonja.job
2014-05-16 15:40 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-05-16 15:39 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\TAPI
2014-05-16 15:25 - 2014-02-02 23:51 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-05-16 15:18 - 2014-05-16 15:18 - 00001113 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-05-16 15:18 - 2014-05-16 15:18 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-05-16 15:18 - 2014-05-16 15:18 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-05-16 15:18 - 2014-05-16 15:18 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-05-16 15:17 - 2014-05-16 15:14 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Sonja\Downloads\mbam-setup-2.0.1.1004.exe
2014-05-16 15:09 - 2014-02-13 16:22 - 00000000 ____D () C:\ProgramData\6c4825cf40a8ac2e
2014-05-16 14:54 - 2014-05-16 14:54 - 00001275 _____ () C:\Users\Sonja\Desktop\Revo Uninstaller.lnk
2014-05-16 14:54 - 2014-05-16 14:54 - 00000000 ____D () C:\Program Files (x86)\VS Revo Group
2014-05-16 14:54 - 2014-05-16 14:53 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Sonja\Downloads\revosetup95.exe
2014-05-16 14:40 - 2014-01-13 18:24 - 00003160 _____ () C:\Windows\System32\Tasks\HPCeeScheduleForSonja
2014-05-16 14:40 - 2014-01-11 21:20 - 00000000 ____D () C:\Users\Sonja
2014-05-16 14:28 - 2014-01-11 21:24 - 00000000 ___RD () C:\Users\Sonja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-05-16 14:28 - 2014-01-11 21:24 - 00000000 ___RD () C:\Users\Sonja\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
2014-05-15 17:00 - 2012-07-26 10:12 - 00000000 ___RD () C:\Windows\ToastData
2014-05-15 17:00 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-15 17:00 - 2012-07-26 10:12 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2014-05-15 16:59 - 2014-01-11 21:20 - 01791925 _____ () C:\Windows\WindowsUpdate.log
2014-05-15 16:59 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\system32\SecureBootUpdates
2014-05-15 16:59 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files\Windows Defender
2014-05-15 16:59 - 2012-07-26 10:12 - 00000000 ____D () C:\Program Files (x86)\Windows Defender
2014-05-14 16:41 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-05-14 16:31 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\rescache
2014-05-14 15:00 - 2014-02-21 21:01 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-05-14 14:59 - 2014-05-14 14:59 - 00000000 ____D () C:\Program Files\Common Files\DESIGNER
2014-05-14 14:58 - 2014-01-12 23:08 - 00000000 ____D () C:\Windows\system32\MRT
2014-05-14 14:56 - 2014-01-12 23:07 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-05-14 14:56 - 2012-07-26 07:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-05-14 13:30 - 2014-05-14 13:30 - 00000000 ____D () C:\Windows\System32\Tasks\Norton Internet Security
2014-05-14 13:25 - 2013-12-04 19:30 - 00000000 ____D () C:\Windows\system32\Drivers\NISx64
2014-05-14 13:25 - 2012-07-26 10:12 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-05-14 13:24 - 2013-12-04 19:31 - 00003234 _____ () C:\Windows\System32\Tasks\Norton WSC Integration
2014-05-14 13:24 - 2013-12-04 19:31 - 00002508 _____ () C:\Users\Public\Desktop\Norton Internet Security.lnk
2014-05-14 13:24 - 2013-12-04 19:30 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
2014-05-14 13:22 - 2014-05-14 13:21 - 00297224 _____ () C:\Windows\Minidump\051414-63125-01.dmp
2014-05-14 13:21 - 2014-02-01 23:37 - 00000000 ____D () C:\Windows\Minidump
2014-05-14 13:20 - 2014-02-01 23:36 - 665766305 _____ () C:\Windows\MEMORY.DMP
2014-05-14 13:20 - 2014-01-11 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-05-14 13:06 - 2014-05-14 13:06 - 00010574 _____ () C:\Users\Sonja\Desktop\Gmer.txt
2014-05-14 12:59 - 2014-05-14 12:59 - 00380416 _____ () C:\Users\Sonja\Desktop\Gmer-19357.exe
2014-05-14 12:54 - 2014-05-14 12:54 - 00036535 _____ () C:\Users\Sonja\Desktop\Addition.txt
2014-05-14 12:48 - 2014-05-14 12:48 - 00000472 _____ () C:\Users\Sonja\Desktop\defogger_disable.log
2014-05-14 12:48 - 2014-05-14 12:48 - 00000000 _____ () C:\Users\Sonja\defogger_reenable
2014-05-14 12:46 - 2014-05-14 12:46 - 00050477 _____ () C:\Users\Sonja\Desktop\Defogger.exe
2014-05-14 12:27 - 2014-02-02 23:51 - 00003772 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-05-12 13:07 - 2014-05-12 13:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-05-12 11:55 - 2014-01-20 22:18 - 00000052 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-05-12 11:55 - 2014-01-20 22:18 - 00000000 _____ () C:\Windows\system32\HP_ActiveX_Patch_NOT_DETECTED.txt
2014-05-07 11:36 - 2012-07-26 10:12 - 00000000 ____D () C:\Windows\WinStore
2014-05-06 07:14 - 2014-05-14 12:32 - 19274752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-05-06 07:14 - 2014-05-14 12:32 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-05-06 05:48 - 2014-05-14 12:32 - 14367232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-05-06 05:48 - 2014-05-14 12:32 - 00080384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-05-06 05:37 - 2014-05-14 12:32 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-05-06 05:26 - 2014-05-14 12:32 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-05-01 22:37 - 2014-01-14 20:36 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-05-01 22:37 - 2014-01-14 20:36 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-04-28 11:43 - 2014-04-28 11:39 - 00000000 ____D () C:\Users\Sonja\Desktop\Wohnung
2014-04-28 11:42 - 2014-04-28 11:41 - 00000000 ____D () C:\Users\Sonja\Desktop\FH
2014-04-28 11:33 - 2014-02-05 09:28 - 00055808 ___SH () C:\Users\Sonja\Desktop\Thumbs.db
2014-04-24 12:30 - 2014-05-05 15:28 - 00061120 _____ (StdLib) C:\Windows\system32\Drivers\{f727685b-ed90-4adc-8eec-8234574a91e6}Gw64.sys
2014-04-19 11:39 - 2014-05-07 10:48 - 00628024 _____ (Microsoft Corporation) C:\Windows\system32\NotificationUI.exe
2014-04-19 10:45 - 2014-05-07 10:48 - 00693760 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-04-19 10:45 - 2014-05-07 10:48 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-04-19 08:57 - 2014-05-07 10:48 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-04-19 08:57 - 2014-05-07 10:48 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
Some content of TEMP:
====================
C:\Users\Sonja\AppData\Local\Temp\38686uninstall.exe
C:\Users\Sonja\AppData\Local\Temp\77595uninstall.exe
C:\Users\Sonja\AppData\Local\Temp\COMAP.EXE
C:\Users\Sonja\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Sonja\AppData\Local\Temp\drm_dyndata_7260005.dll
C:\Users\Sonja\AppData\Local\Temp\Extract.exe
C:\Users\Sonja\AppData\Local\Temp\htmlayout.dll
C:\Users\Sonja\AppData\Local\Temp\Quarantine.exe
C:\Users\Sonja\AppData\Local\Temp\SP64996.exe
C:\Users\Sonja\AppData\Local\Temp\SP64999.exe
C:\Users\Sonja\AppData\Local\Temp\SP65792.exe
C:\Users\Sonja\AppData\Local\Temp\SP65823.exe
C:\Users\Sonja\AppData\Local\Temp\Sqlite3.dll
C:\Users\Sonja\AppData\Local\Temp\toolbar559650156.exe
C:\Users\Sonja\AppData\Local\Temp\VuuPC.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe
[2014-05-14 12:33] - [2014-04-12 11:10] - 0578048 ____A (Microsoft Corporation) 75DD70A14145499C9F7D903CF9A8C91B
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-05-07 11:36
==================== End Of Log ============================ --- --- --- |